// ThreatHuntingLabs  ·  writeup

The Recurring Impostor — Flash Hunt

ThreatHuntingLabs EDR TelemetrySysmonWindows DefenderHunt.ioKQL

Case Context

A Flash Hunt on Threat Hunting Labs — the platform’s rapid, single-session investigation format, distinct from the guided multi-hour cases.

Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.

A Windows workstation alert on a scheduled task with a suspicious target path traced back three levels to the real point of execution, then forward through a recurring persistence mechanism disguised as a legitimate system process, a Severe antivirus detection that was logged as resolved but never actually removed the payload, a destructive lockout stage two days later, and a masqueraded re-execution on day three. Enrichment against the attacker’s own external infrastructure recovered an exposed staging server, cross-confirming the toolkit and clearing up conflicting malware-family labels across four different sources.

Techniques Encountered

Eleven MITRE ATT&CK techniques surfaced during the hunt, spanning execution, scheduled-task and autostart persistence, masquerading, defense evasion, and command-and-control:

MITRE ATT&CK techniques encountered during the hunt

Prioritising Findings — Pyramid of Pain

28 findings came out of the hunt, weighted by how costly each is for the attacker to change — hash values and IP addresses sit at the bottom and are trivial to rotate, while the TTPs and tooling behind the persistence mechanism sit at the top and are far more durable to detect on:

Pyramid of Pain breakdown of findings from the hunt

What I Practiced

Credential

Earned a Distinction (85% score) on this Flash Hunt.

Flash Hunt Distinction badge

Verify: https://www.threathuntinglabs.com/badges/b675dedd-ccde-45a2-8eaa-ef2e5d7544da