Highlight: THM: Advent of Cyber 2022 [Day 11] Memory Forensics Not all gifts are nice
The elves in Santa's Security Operations Centre (SSOC) are hard at work checking their monitoring dashboards when Elf McDave, one of the workshop employees, knocks on the door. The elf says, "I've just clicked on something and now my workstation is behaving in all kinds of weird ways. Can you take a look?".
Elf McSkidy tasks you, Elf McBlue, to investigate the workstation. Running down to the workshop floor, you see a command prompt running some code. Uh oh! This is not good. You immediately create a memory dump of the workstation and place this dump onto your employee-issued USB stick, returning to the SSOC for further analysis.
[https://tryhackme.com/room/adventofcyber4](https://tryhackme.com/room/adventofcyber4) -- Watch live at https://www.twitch.tv/msec