Operation Midnight Run

PRACTICAL · WINDOWS · difficulty 2 · ~25 min · 28 steps

PsExec-style lateral movement on a domain-joined Windows server.

Briefing

02:47 local. EDR flagged WIN-FILE-02: a service binary executing from the ADMIN$ share followed by suspicious PowerShell spawning under a backup service account. This smells like lateral movement after a phishing foothold elsewhere in the domain. You are on the host with local admin. Live-response only — no reboot, no imaging, GO.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$