← Back to list

TryHackMe : Trooper Writeup

Question1 : What kind of phishing campaign does APT X use as part of their TTPs ?

Madhanraj · 2025-01-08 15:06 · 0 claps · 2.6 min read
#threat-intelligence #tryhackme #trooper #cybersecurity
Open on Medium ↗
Wiki topics: MKT · Marketing · General 🔒 · Cybersecurity

TryHackMe : Trooper Writeup

Question1 : What kind of phishing campaign does APT X use as part of their TTPs ?

In the report you see

Question2: What is the name of the malware used by APT X?

In the report,

Question3: What is the malware’s STIX ID?

Go to opencti and select the arsenel menu and search the USBferry

Question4: With the use of a USB, what technique did APT X use for initial access?

In the above menu, click the knowledge and the right side menu click the attack pattern and also select the kill chain view

Question5: What is the identity of APT X?

Question6: On OpenCTI, how many Attack Pattern techniques are associated with the APT?

see there is an 39 patterns

Question7: What is the name of the tool linked to the APT?

click the tools menu. there you see

Question8: Load up the Navigator. What is the sub-technique used by the APT under Valid Accounts ?

Question9 : Under what Tactics does the technique above fall ?

The “local accounts” technique can be classified under four distinct tactics in the MITRE ATT&CK framework: Initial Access, Persistence, Defense Evasion, and Privilege Escalation. This classification highlights the versatility and impact of local accounts in a cybersecurity context.

Question10 : What technique is the group known for using under the tactic Collection?

Thanks for reading !


메타데이터
post_id
bb439fdeafa9
slug
tryhackme-trooper-writeup-bb439fdeafa9
url
https://medium.com/@m4dhanraj/tryhackme-trooper-writeup-bb439fdeafa9
canonical_url
https://medium.com/@m4dhanraj/tryhackme-trooper-writeup-bb439fdeafa9
author_url
https://medium.com/@m4dhanraj
status
ok
fetched_at
2026-08-24 21:15:08