XDR: Operation Global Dagger 2
继续调查Operation Global Dagger 1中的异常行为和攻击活动,利用Microsoft Defender XDR检测恶意持续活动、执行、安全工具规避及横向移动。 2025-10-4 08:39:10 Author: infosecwriteups.com(查看原文) 阅读量:23 收藏

THM{0x416469747961204D6163686972616A75}

Investigate and detect potential threats across your environment.

Press enter or click to view image in full size

Friendly Link :

Task 1: Introduction

Continuing to investigate the incident from Operation Global Dagger 1, we need to investigate more unusual user and machine behaviours, some persistent activities, malicious executions, and attempts by an attacker to disable the organisation’s security solution.

Room Objectives

In the next task, you will be required to use different Microsoft Defender XDR products and features to detect and investigate various activities within your organisation, such as:

  • Malicious persistence activities
  • Malicious executions on devices
  • Evasion of security tools
  • Lateral movement

Prerequisites

Task 2: Lab Instructions

Kindly follow the instructions below to access your lab on the next task.

On your lab task, Lab: Detect and Investigate: Task 3, click the Cloud Details button.


文章来源: https://infosecwriteups.com/xdr-operation-global-dagger-2-65ba900bc51f?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh