@RealTryHackMe #AdventOfCyber Series: Challenge 23 – PowershELlF Magic #TisTheSeasonForHacking

Another day, another challenge…

In this post, we’re starting a new series the Advent of Cyber series that is hosted by TryHackMe. This is the third year of the Advent of Cyber where a challenge is released everyday leading to Christmas. In total there will be 25 challenges. In these challenges, we’re McSkidy an elf trying to save Christmas.

In our twenty-third challenge, we’re presented with a scenario where one of the admins from Elf Dome Enterprises realizes his password file is missing from his desktop. McSkidy suspects that a previous phishing attempt was successful and is on the hunt to figure out what happened.

The topic(s) explored in this challenge are PowerShell and Event Viewer. PowerShell is used to automate day-to-day tasks. PowerShell can also be used for nefarious activity as well. PowerShell is available on Windows, Linux, and macOS. The last concept Event Viewer is a logging system. All actions in Windows are classified as an event and has a specific event ID and record ID. Event Viewer can be helpful as we can filter all events for a particular day, activity/action, and/or provider (such as PowerShell). This will be helpful for the challenge.

Can McSkidy figure out how the admin from Elf Dome Enterprises lost his password file? Find out below!

