root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat elevating-movement.md
// Blue Team & SOC

Elevating Movement

3 Mar 2025 · 10 min read · root access
Elevating Movement is a Windows DFIR investigation on TryHackMe. After DeceptiTech's network collapse, you reconstruct Stage #2 of the attack on the SRV-IT-QA server: how the intruder logged in over RDP with Emily Ross's stolen credentials, planted a Meterpreter backdoor for persistence and privesc, dumped LSASS to steal hashes, and pivoted laterally using domain admin matthew.collins. Everything is solved by reading Event Logs, file-system artifacts, and a reconstructed timeline.
PlatformTryHackMe
CategoryBlue Team & SOC (DFIR / Windows Forensics)
DifficultyHard
RoomElevating Movement

Scenario context

DeceptiTech runs a hybrid infrastructure: a traditional on-prem Active Directory domain (~50 users) and an isolated AWS-hosted product platform. The attack unfolded in several stages; this room focuses on Stage #2, where the attacker reuses Emily Ross's credentials (stolen in Stage #1) to access SRV-IT-QA, a QA server where Emily holds local admin privileges.

Pre-investigation facts that steer the analysis:

  • Emily's domain credentials were stolen.
  • The server became “unstable” right after a motherboard replacement (suspicious timing).
  • Emily accessed the machine with a local admin account.
  • Other IT administrators log in frequently (legitimate noise).
  • The attacker had access on Monday, Day 4.
🔒 Clearance required

This content is Root Access only. Everything else on the site — the free tier, the whole public library — stays open.

See Root Access plans

No account? Create one free then upgrade from your console.