Questions
1. On what day was Glitch_Malware last logged in?
Answer format: DD/MM/YYYY
data:image/s3,"s3://crabby-images/8674f/8674f50ea991be513f29089e41c7f9b7ef6ccdc5" alt=""
07/11/2024
2. What event ID shows the login of the Glitch_Malware user?
data:image/s3,"s3://crabby-images/78b33/78b336c701dfe100f0caed6add1d0969d8b0983d" alt=""
4624
3. Read the PowerShell history of the Administrator account. What was the command that was used to enumerate Active Directory users?
notepad “$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt”
data:image/s3,"s3://crabby-images/6c3d7/6c3d70cbc1bf9c5e583594134b18724bb3f21aa7" alt=""
data:image/s3,"s3://crabby-images/2d1d6/2d1d6a496ed2b3a04ab70f368c8a380207c32e97" alt=""
Get-ADUser -Filter * -Properties MemberOf | Select-Object Name
4. Look in the PowerShell log file located in Application and Services Logs -> Windows PowerShell
. What was Glitch_Malware’s set password?
data:image/s3,"s3://crabby-images/dd36e/dd36e8a49c3a9ed37973c8388ab1374539d90200" alt=""
SuperSecretP@ssw0rd!
5. Review the Group Policy Objects present on the machine. What is the name of the installed GPO?
Get-GPO -All
data:image/s3,"s3://crabby-images/e6abe/e6abeb5ce6f5f3dcfc119df919667ac949fd2f29" alt=""