A Flash Hunt on Threat Hunting Labs — the platform’s rapid, single-session investigation format, distinct from the guided multi-hour cases.
Threat Hunting Labs has a strict no-public-writeup policy on active labs to protect scoring and leaderboards for other users, so this page is intentionally an overview: what I did and what I found, not the queries or the specific answers that got me there.
A Windows workstation alert on a scheduled task with a suspicious target path traced back three levels to the real point of execution, then forward through a recurring persistence mechanism disguised as a legitimate system process, a Severe antivirus detection that was logged as resolved but never actually removed the payload, a destructive lockout stage two days later, and a masqueraded re-execution on day three. Enrichment against the attacker’s own external infrastructure recovered an exposed staging server, cross-confirming the toolkit and clearing up conflicting malware-family labels across four different sources.
Eleven MITRE ATT&CK techniques surfaced during the hunt, spanning execution, scheduled-task and autostart persistence, masquerading, defense evasion, and command-and-control:

28 findings came out of the hunt, weighted by how costly each is for the attacker to change — hash values and IP addresses sit at the bottom and are trivial to rotate, while the TTPs and tooling behind the persistence mechanism sit at the top and are far more durable to detect on:

Earned a Distinction (85% score) on this Flash Hunt.
Verify: https://www.threathuntinglabs.com/badges/b675dedd-ccde-45a2-8eaa-ef2e5d7544da