Fileless persistence on a jump host — WMI event subscription + scheduled tasks driving signed system binaries, ambiguous admin-vs-attacker, ~30-day dwell
A extremely-hard Cybersecurity scenario on Living-off-the-Land Persistence.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · lotl-persistence-wmi-scheduled-task
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Fileless WMI/LOLBin persistence triage
- Memory-first evidence under ambiguity
- Event Triggered Execution: WMI Event Subscription · PersistenceT1546 · TA0003MappedHigh confidence
Trains triage of WMI permanent event subscription persistence.
- Command and Scripting Interpreter · ExecutionT1059 · TA0002MappedMedium confidence
Trains analysis of encoded PowerShell driven by signed binaries.
- Process Activity AnalysisD3-PAUMappedHigh confidence
Trains process-lineage analysis of living-off-the-land activity.
- File AnalysisD3-FAPartialLow confidence
Trains recovery of a memory-only artifact when nothing is left on disk.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection of fileless persistence under partial EDR.
- Analysis · RespondRS.AN · RSMappedHigh confidence
Trains the admin-vs-attacker disambiguation analysis.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains memory-first triage of ambiguous, signed-binary persistence.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedMedium confidence
Trains preserve-then-isolate of a privileged jump host.
- Detecting Relevant Threats and TTPs3.AMappedHigh confidence
Trains detection-engineering for WMI/LOLBin tradecraft.
- Mitigating Known Vulnerabilities1.EPartialLow confidence
Trains closing the EDR and patch gaps that hid the dwell.
- Audit Log ManagementControl 8MappedHigh confidence
Trains the logging the fileless investigation depends on.
- Account ManagementControl 5MappedMedium confidence
Trains retiring the shared admin account that broke attribution.