- Tools: Registry Explorer, Event Log Explorer, NTFS Log Tracker, MFTECmd, VirusTotal
- Technical Concepts: Group Policy Objects (GPOs), Windows Defender Exclusions, Scheduled Tasks, Windows Management Instrumentation (WMIC), Windows Boot Manager, Wiper Malware, Update Sequence Number (USN)
- References:
* Registry Explorer: Download Link
* Event Log Explorer: Download Link
* NTFS Log Tracker: Download Link
* MFTECmd: Download Link
* VirusTotal: https://www.virustotal.com/gui/
A critical network infrastructure has been hit by a cyberattack, causing significant operational disruptions, system outages, and compromised machines. Public message boards are displaying politically charged messages, and several systems have been wiped, leading to widespread service failures. Initial investigations reveal that attackers compromised the Active Directory (AD) system and deployed wiper malware across multiple machines.
An alert employee noticed suspicious activity during the attack and immediately powered down several key systems, preventing the malware from completely wiping the entire network. However, damage has been done, and your team is tasked with investigating the extent of the compromise.
You have been provided with forensic artifacts collected via KAPE SANS Triage from one of the affected machines. Your objective is to determine how the attackers gained access, the scope of the malware's deployment, and what critical systems or data were impacted before the shutdown.
Group Policy Objects (GPOs) are a centralized way to manage and configure settings for users and co…