← Back to list

Trooper | TryHackMe Walkthrough

SOC Level-1 > Cyber Threat Intelligence > Trooper

Jainam Panchal · 2025-03-17 04:24 · 2 claps · 4.0 min read
#tryhackme-walkthrough #tryhackme-write-up #soc #trooper
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Trooper | TryHackMe Walkthrough

SOC Level-1 > Cyber Threat Intelligence > Trooper

Author: Jainam Panchal

Linkedin: www.linkedin.com/in/jainam-panchal

Email: jainam.panchal0902@gmail.com

TryHackMe:

Trooper

Task 1 Who’s The Threat?

What kind of phishing campaign does APT X use as part of their TTPs?

This is found in one of the first line of the report:

Answer: spear-phishing emails

What is the name of the malware used by APT X?

If you read on you can read about APT X’s latest malware attack or you can read it on the second para in the report:

Answer : USBferry

What is the malware’s STIX ID?

Visit the OpenCTI Dashboard at http://<target ip>:8080. You will be met by a dashboard, and let’s try searching for USBferry through the topright search field:

Any of the entries will give the answer but go ahead and select the bottom one (entity) and In the top left corner you will see the STIX ID:

Answer : malware — 5d0ea014–1ce9–5d5c-bcc7-f625a07907d0

With the use of a USB, what technique did APT X use for initial access?

This has multiple solutions I picked the easiest for myself.

Go to Mitre Att&ck website. Select Tactics -> Enterprise

Then within the “Enterprise” section under Tactics on the left you can find “Initial Access”

You can look at the Knowledge tab of the OpenCTI page on USBferry. Here we can see the ATT&CK Matrix and Here the correct technique is highlighted under Lateral-movement:

Once we identify the key details, we just need to find the matching answer. From the report, we know the attackers use USB (Removable Media) and operate within Air-gapped networks.

Instead of going through all results, we can focus on those related to USB. Among them, only one specifically mentions Air-gapped networks — and that is our answer.

Answer : Replication Through Removable Media

What is the identity of APT X?

On a previous screenshot, on the USBFERRY malware detail page, you can see that the identity of APT X is Tropic Trooper, a unaffiliated threat group that has led target campaigns against targets in Taiwan, the Philippines, and Hong Kong.

Answer : Tropic Trooper

On OpenCTI, how many Attack Pattern techniques are associated with the APT?

Search for Tropic Trooper on Intrusion Set and you will get to the following page and Now, go to the Knowledge tab and you will see the relationships the Intrusion Set (APT) has to other entities :

Answer: 39

What is the name of the tool linked to the APT?

Continue where we were. Just click on Tools on the side menu. Here it will list one tool:

Answer : BITSAdmin

Load up the Navigator. What is the sub-technique used by the APT under Valid Accounts?

Now open up the ATT&CK Navigator, likely at the same IP address and OpenCTI, but running on a different port.

Here we are at the familiar ATT&CK Matrix and Now, the question refers to Valid Accounts which is under Persistence. Now, if you press on the right side of the Valid Accounts technique the sub-techniques become visible.

Answer: local accounts

Under what Tactics does the technique above fall?

There are four different columns (tactics) in which the Valid Accounts technique i used. We just have to write the different tactics (column names) in which Valid Accounts exists. We do this in order left to right.

Answer : Initial Access, Persistence, Defense Evasion and Privilege Escalation

What technique is the group known for using under the tactic Collection?

Find the Collection column (tactic) and find the highlighted technique.

Answer : Automated Collection

A big thanks to Maitri for Solving and helping this!!

Review:

This was a really fun and engaging box. If you’re familiar with OpenCTI and the MITRE ATT&CK framework, it feels like an easy and enjoyable experience.

However, for those new to these frameworks, differentiating Tactics, Techniques, and Procedures (TTPs) can be challenging at first. MITRE might seem overwhelming initially, but once you understand it, you’ll realize how valuable and intuitive it is.

I highly recommend giving this box a try — it’s a great learning experience.

Have fun, and remember, the rabbit hole goes deep! 😃


메타데이터
post_id
bf4bdc29d18a
slug
trooper-tryhackme-walkthrough-bf4bdc29d18a
url
https://medium.com/@jainam.panchal0902/trooper-tryhackme-walkthrough-bf4bdc29d18a
canonical_url
https://medium.com/@jainam.panchal0902/trooper-tryhackme-walkthrough-bf4bdc29d18a
author_url
https://medium.com/@jainam.panchal0902
status
ok
fetched_at
2026-08-24 21:15:08