Part of a 2-lab Flash Hunt case on Threat Hunting Labs: NightShade C2 Multi-Stage Infection. This lab is the Threat Hunt angle (1 of 2) — hunting the multi-stage installer chain end-to-end from raw EDR telemetry.
Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.
A user-executed MSI installer chains through several script interpreters before landing on a legitimate, signed portable runtime — repurposed as a fetch-and-eval command-and-control client rather than for anything it ships to do. The intrusion establishes persistence at both user and SYSTEM scope through different mechanisms, and later escalates privilege via a UAC-bypass technique, all using signed, trusted binaries throughout — no unsigned artifacts anywhere in the chain.
Nine MITRE ATT&CK techniques surfaced across the hunt, spanning user-driven initial execution, layered scripting interpreters, dual persistence mechanisms (user Startup + SYSTEM scheduled task), UAC-bypass privilege escalation, tool transfer, web-based C2, and masquerading:
T1204.002 T1059.001 T1059.005 T1547.001 T1053.005 T1548.002 T1105 T1071.001 T1036.005
Eighteen findings came out of the hunt, weighted by how costly each is for the attacker to change:

Earned a Distinction (100% score) on this Flash Hunt case.
Verify: https://www.threathuntinglabs.com/badges/eb22ce0d-fca8-4dc0-8d71-20394cef79ff