AA24-060A Phobos Intrusion Command and Exfiltration Research
Trace a Phobos intrusion from exposed RDP and loader behavior through firewall changes, credential access, exfiltration,...
6 questions · 45 minResearch CISA's official AA24-109A advisory. Use the current advisory text to verify actor associations, hypervisor chronology, named accounts, driver abuse, virtual-disk credential access, and encryptor behavior.
Sign in to answer the questions, save your result and receive a certificate when you pass.