pwnedDC memory forensic challenge


This lab is made by CyberDefenders.

Lab Scenario

“An ActiveDirectory compromise case: adversaries were able to take over the corporate domain controller. As a soc analyst, Investigate the case and reveal the Who, When, What, Where, Why, and How.”

Downloading the Memory Dump / Running on the Cloud Lab

Please visit the lab official link to download it.

Used Tools


“Use Win2016x64_14393 profile with volatility2 to analyze the memory dump”

Additional Details

This lab is under the Pro edition, so you need to have an active subscription (not free) to try it.


In this blog, I briefly notified you about a newly released memory forensic challenge.

~ Cya in the Next One

Leave a Reply