Every command this range teaches, decoded. Pick one on the left, or search above.
PRACTICAL · WINDOWS · difficulty 2 · ~25 min · 28 steps
PsExec-style lateral movement on a domain-joined Windows server.
02:47 local. EDR flagged WIN-FILE-02: a service binary executing from the ADMIN$ share followed by suspicious PowerShell spawning under a backup service account. This smells like lateral movement after a phishing foothold elsewhere in the domain. You are on the host with local admin. Live-response only — no reboot, no imaging, GO.