Operation Residue

FORENSICS · LINUX · difficulty 5 · ~45 min · 18 steps

Sixteen gigabytes of RAM from a host that looked clean. Every process on it is a Windows process. One is lying.

Briefing

A finance workstation was flagged by a firewall rule and nothing else — one outbound session to an address on a watchlist, from a process the endpoint agent considers legitimate and signed. Memory was captured before the machine was powered off. The disk has since been imaged and is clean: no unusual files, no scheduled tasks, no services, no persistence anywhere on it. It never touched the disk. Everything that ever ran on this machine exists only in the sixteen gigabytes you are holding, and the process it ran inside still has the right name, the right path and the right signature.

Objectives

Return to the range lobby

THREAT FEED ▲ lateral movement via wmiexec up 18% ▲ new loader family 'GHOSTPULSE' staging via DLL search-order hijack ▲ prompt injection in support queues now routine ▲ cron persistence campaign targeting exposed SSH ▲ poisoned model weights on public hubs ▲ remember: trust nothing, hash everything ▲
operator@dojo:~$