Points: 564

Tags: windbg rev forensics 

Poll rating:

The SOC team of the BrighSoul QPL (Quantum Physic Labs) is continuously monitoring HTTP proxy and DNS outbound traffic and has identified suspicious DNS traffic to the server authoritative (NS) for the domain thedarkestside.org.

Upon investigation, they presume that an internal windows workstation with has been compromised with a Colbalt Strike beacon running as the executable named ntupdate.exe. The workstation belongs to the R&D team and they are suspicions that files containing critical Intellectual Property information have been exfiltrated.

ou are a member of the CSIRT team and your objective is to identify which data has been leaked. You receive the following information:

Writeups

ActionRatingAuthor team
Read writeup
not rated
ret2school
You need to authenticate and join a team to post writeups