Operation Iron Ledger

PRACTICAL · LINUX · difficulty 1 · ~15 min · 20 steps

Post-breach persistence audit on a Debian build server.

Briefing

A vendor notified us that deb-build-03 appears in a leaked credential dump. No active attack detected — but anything that had access may have left persistence behind. Run a methodical audit: users, SSH keys, cron, services, and autostart.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$