The Advent of Cyber: Day 4: Atomic Red Team - I’m all atomic inside! (TryHackMe)

J3bitokJ3bitok
2 min read

In this article, we’ll cover the Atomic Red Team - I’m all atomic inside! The write-up is called the Day 4 challenge of the Advent of Cyber event challenge. It was interesting to understand and navigate through the Cyber Attacks & the Kill Chain, the Atomic Red Library which is a red team test case that is mapped to the MITRE ATT&CK framework. We’re still at Wareville for SOC-mas!

As Glitch continues to prepare for SOC-mas and fortifies Wareville's security, he decides to conduct an attack simulation that would mimic a ransomware attack across the environment. He is unsure of the correct detection metrics to implement for this test and asks you for help. Your task is to identify the correct atomic test to run that will take advantage of a command and scripting interpreter, conduct the test, and extract valuable artifacts that would be used to craft a detection rule.

Answer the questions below

  1. What was the flag found in the .txt file that is found in the same directory as the PhishingAttachment.xslm artefact? THM{GlitchTestingForSpearphishing}

  2. What ATT&CK technique ID would be our point of interest? T1059

  3. What ATT&CK subtechnique ID focuses on the Windows Command Shell? T1059.003

  4. What is the name of the Atomic Test to be simulated? Simulate BlackByte Ransomware Print Bombing

  5. What is the name of the file used in the test? Wareville_Ransomware.txt

  6. What is the flag found from this Atomic Test? THM{R2xpdGNoIGlzIG5vdCB0aGUgZW5lbXk=}

  7. Learn more about the Atomic Red Team via the linked room.

Thank you for reading through this article. You can leave a comment with your thoughts: areas to improve or other suggestions and questions if any. Till the next one, stay secure!

0
Subscribe to my newsletter

Read articles from J3bitok directly inside your inbox. Subscribe to the newsletter, and don't miss out.

Written by

J3bitok
J3bitok

Software Developer Learning Cloud and Cybersecurity Open for roles * If you're in the early stages of your career in software development (student or still looking for an entry-level role) and in need of mentorship you can book a session with me on Mentorlst.com.