Free Windows Security Terminal Lab: Practice Endpoint Investigation from the Command Line
Windows systems generate a huge amount of useful security information.
Running processes, network connections, user accounts, scheduled tasks, startup programs, privileges, and files can all provide evidence during a security investigation.
But knowing that this information exists is different from knowing how to find it.
The CertInstructor Windows Security Terminal Lab is a free browser-based training environment designed to help learners practice Windows security investigation directly from a simulated command line.
Launch the lab:
https://go.certinstructor.org/labs/windows-terminal-lab/
The lab contains 8 investigation missions covering suspicious processes, attacker connections, backdoor accounts, privilege escalation, persistence, hacking tools, command-and-control traffic, and startup mechanisms.
No Windows virtual machine or software installation is required.
Everything runs safely inside your browser.
What Is the Windows Security Terminal Lab?
The Windows Security Terminal Lab puts you in front of a simulated Windows command prompt and asks you to investigate a potentially compromised workstation.
Instead of simply reading descriptions of Windows commands, you use them to answer real investigative questions.
For example:
What process looks malicious?
Which external IP is communicating with the system?
Did the attacker create a new user?
Is there a suspicious scheduled task?
Was malware configured to run automatically?
The training workflow is simple:
Question → Command → Output → Evidence → Answer
This makes the lab useful for learners who want to understand how command-line tools can support security operations and incident response.
Mission 1: Find the Malicious Process
The first mission begins with process investigation.
Try:
tasklist
or the PowerShell equivalent:
Get-Process
The output shows processes running on the simulated workstation.
Your task is to identify a process that does not belong.
This exercise teaches an important endpoint-investigation skill:
Attackers often try to look legitimate.
Malware may use a filename that resembles a Windows process.
For example, legitimate Windows processes include names such as:
svchost.exe
csrss.exe
lsass.exe
A malicious executable may attempt to imitate one of these while adding an unusual suffix or modification.
Do not simply search for a filename that looks obviously malicious.
Compare suspicious names with what legitimate Windows processes normally look like.
Mission 2: Detect the Attacker Connection
Once a suspicious process has been identified, investigate its network activity.
Try:
netstat -ano
or:
Get-NetTCPConnection
These commands allow you to inspect active TCP connections.
Pay attention to:
-
Local IP addresses
-
Local ports
-
Remote IP addresses
-
Remote ports
-
Connection state
-
Process IDs
The key skill is correlation.
If you found a suspicious process in Mission 1, determine whether the same process ID appears in an unusual network connection.
This produces stronger evidence:
Suspicious process + suspicious outbound connection
is more meaningful than either observation alone.
Understanding Process IDs
A process ID, or PID, allows you to connect different types of endpoint evidence.
Suppose tasklist shows:
SuspiciousProcess.exe → PID 14320
and netstat -ano shows:
PID 14320 → External IP → Port 4444
Now you can connect the process to its network activity.
This is an important investigation habit:
Do not treat command output as isolated information. Correlate it.
Mission 3: Find the Backdoor User Account
Attackers may create additional accounts to maintain access to a compromised system.
Use:
net user
to list local user accounts.
Look for anything unexpected.
A suspicious account might:
-
Have an unusual name
-
Have been created recently
-
Belong to the Administrators group
-
Have password expiration disabled
-
Be associated with unusual logon activity
You can investigate a specific account using:
net user <username>
Another useful command is:
net localgroup administrators
This allows you to check which users have local administrative privileges.
The important question is not simply:
Does this username look strange?
Instead ask:
Does this account make sense on this workstation?
Mission 4: Check Privilege Escalation
The next mission focuses on Windows privileges.
Run:
whoami /priv
Windows privileges control what actions a user or process is allowed to perform.
Some privileges deserve particular attention during an incident investigation.
For example, SeDebugPrivilege can allow a process to interact with or debug other processes.
In the wrong context, powerful privileges can help an attacker access sensitive processes or credentials.
Other privileges may also deserve attention depending on the situation.
The lesson is broader than memorizing one privilege name:
Excessive privileges increase the potential impact of a compromise.
This connects directly to the principle of least privilege.
Mission 5: Investigate Scheduled Task Persistence
An attacker does not always want to execute malware only once.
They may want the malware to return after reboot or user logon.
One common persistence mechanism is a scheduled task.
Try:
schtasks
Review the scheduled tasks carefully.
Look for:
-
Unexpected names
-
Tasks created at unusual times
-
Commands launching unknown executables
-
Programs stored in user-writable directories
-
Tasks pretending to be Windows update or maintenance components
The challenge is distinguishing legitimate system activity from something designed to blend in.
Persistence investigation asks:
How does the attacker make sure access survives?
Mission 6: Find Hacking Tools
Attackers may download utilities after compromising a workstation.
Inspect the user's Downloads directory:
dir c:\users\admin\downloads
You may encounter recognizable security or post-exploitation tools.
For example, Mimikatz is widely associated with credential-access activity, while tools such as Netcat can be used for legitimate administration but may also appear in attacker workflows.
Context matters.
A security tool existing somewhere on a computer does not automatically prove compromise.
But a credential-dumping utility suddenly appearing during the same time window as suspicious accounts, malware, and network connections is highly relevant evidence.
This is another reason timeline correlation matters.
Mission 7: Detect Command-and-Control Activity
An attacker may maintain communication with malware through command-and-control infrastructure, often abbreviated as C2.
Use commands such as:
netstat -b
or:
Get-NetTCPConnection
to examine active communication.
The simulated workstation may contain ordinary connections to legitimate services alongside suspicious connections.
Your task is to identify which communication deserves investigation.
Useful questions include:
Is the destination expected?
Which process owns the connection?
Which port is being used?
Does the same destination appear repeatedly?
Does the traffic correlate with a suspicious process?
Attackers may also use ports commonly associated with encrypted web traffic in an attempt to blend into normal network activity.
Therefore:
Common port ≠ automatically legitimate traffic
Context is essential.
Mission 8: Check Startup Persistence
The final mission focuses on programs configured to start automatically.
Try:
wmic startup list
Startup mechanisms are attractive to attackers because they can cause malware to execute whenever a user logs in or the machine starts.
Look for:
-
Unknown executables
-
Strange paths
-
User-profile directories
-
Fake software-update names
-
Programs that correlate with malware discovered earlier
This reinforces another useful incident-response concept:
Attackers often establish more than one persistence mechanism.
For example, the same incident may involve both:
Scheduled Task Persistence
and:
Startup Registry Persistence
Finding one mechanism does not necessarily mean you have found them all.
Useful Commands in the Lab
The simulated terminal supports a range of Windows investigation commands.
System and Network Information
ipconfig
ipconfig /all
hostname
systeminfo
These commands help establish basic context about the workstation.
Identity and Privileges
whoami
whoami /priv
net user
net localgroup administrators
These help you understand which accounts and privileges exist.
Process Investigation
tasklist
Get-Process
These commands help identify running processes and suspicious executables.
Network Investigation
netstat -ano
netstat -b
Get-NetTCPConnection
These help connect processes to network communication.
Persistence Investigation
schtasks
wmic startup list
These can reveal scheduled and startup execution mechanisms.
File Investigation
dir
and directory-specific variations allow you to inspect suspicious files and downloaded tools.
The important goal is not to memorize every command.
Think in terms of investigative questions:
What is running? → tasklist
Who is connected? → netstat
Which accounts exist? → net user
What privileges are enabled? → whoami /priv
What survives reboot? → schtasks / startup entries
This makes the commands much easier to remember.
Use the Suggested Command
Each mission includes a suggested command.
If you are still learning Windows security commands, use it as a starting point.
For example:
Mission: Find the malicious process
Suggested command: tasklist
Run the command.
Read the output.
Then try to determine why one entry deserves attention.
The lab also includes Copy Suggested Command, making it easy to copy the command for study notes.
As you become more comfortable, try solving each mission without relying on the suggestion.
Use Suspicious Highlighting Carefully
The lab includes a Toggle Suspicious Highlight function.
This can help beginners identify potentially important output.
But do not depend on it permanently.
A better progression is:
First attempt: Use highlighting when needed.
Second attempt: Investigate without highlighting.
Later attempts: Explain exactly why the suspicious line matters.
The goal is to move from assisted recognition toward independent analysis.
Use Hints as a Learning Tool
Hints are available when you become stuck.
Try this sequence first:
-
Read the mission.
-
Decide which system information you need.
-
Choose a command.
-
Examine the output.
-
Form a hypothesis.
-
Submit the answer.
-
Use a hint only if necessary.
This encourages active investigation rather than answer memorization.
Randomized Threat Data
One useful feature of the lab is that several incident indicators can vary between sessions.
Examples may include:
-
Attacker IP
-
C2 IP
-
Malware filename
-
Malware PID
-
Backdoor username
-
Internal workstation address
-
Hostname
-
Suspicious port
This means the learning objective is not:
Remember the answer from last time.
Instead:
Learn how to find the answer.
That distinction is extremely important for practical cybersecurity training.
Progress Is Saved
Your progress can be retained locally in your browser.
The lab remembers information such as:
-
Current mission
-
Score
-
Completed missions
-
Hints
-
Command history
-
Current answer
-
Incident dataset
If you reload the page during an investigation, the simulated attacker data does not suddenly change underneath you.
When you want a fresh case, use RESET.
This clears the current progress and allows the lab to generate a new incident dataset.
Build an Investigation Workflow
By the time you complete all eight missions, you will have practiced several stages of endpoint investigation.
A simplified workflow looks like this:
1. Establish system context
Check hostname, network configuration, user identity, and system information.
2. Inspect processes
Look for unusual execution.
3. Examine network connections
Determine which processes are communicating externally.
4. Investigate accounts
Look for unauthorized users and privilege changes.
5. Examine privileges
Identify dangerous or unnecessary permissions.
6. Look for persistence
Check scheduled tasks and startup mechanisms.
7. Inspect suspicious files and tools
Look for post-exploitation artifacts.
8. Identify C2 communication
Determine whether the host is communicating with attacker-controlled infrastructure.
This can be summarized as:
Process → Network → Accounts → Privileges → Persistence → Tools → C2
Think in Relationships, Not Individual Commands
One of the most valuable habits in security investigation is connecting evidence.
Consider this sequence:
tasklist
reveals a suspicious executable.
Then:
netstat -ano
shows the same PID connecting to an external system.
Then:
net user
reveals a recently created administrator account.
Then:
schtasks
shows a task configured to relaunch the suspicious executable.
Then:
wmic startup list
reveals another persistence mechanism.
Now you no longer have isolated suspicious events.
You have an incident story.
This is exactly what security analysis should aim to produce.
Useful for Certification Preparation
The lab can complement learning for certifications that include topics such as:
-
Windows security
-
Incident response
-
Endpoint investigation
-
Privilege escalation
-
Persistence
-
Network connections
-
Command-and-control
-
Credential access
-
Security operations
The scenarios are especially relevant to learners preparing for certifications such as:
-
CompTIA Security+
-
CompTIA CySA+
-
CompTIA PenTest+
-
CHFI
-
CEH
The lab is not intended to reproduce an entire certification exam.
Its purpose is to help make security concepts more concrete through interaction.
How This Lab Differs From the Windows IR Simulator
The two Windows labs are related, but they serve different purposes.
Windows Security Terminal Lab
Focuses on:
Command → Output → Indicator
You practice investigating Windows using terminal commands across eight focused missions.
Windows Incident Response Simulator
Focuses on:
Incident → Evidence → Timeline → Attack Chain → Root Cause
It is a larger story-driven case investigation.
A useful progression is therefore:
Windows Terminal Lab
Learn the individual investigative tools.
↓
Windows IR Simulator
Use those ideas to reconstruct a complete compromise.
This makes the two apps complementary rather than redundant.
Who Is This Lab For?
The Windows Security Terminal Lab is suitable for:
-
Cybersecurity students
-
SOC analyst learners
-
Incident response beginners
-
Blue-team students
-
Windows administrators moving into security
-
Digital forensics learners
-
Certification candidates
-
Help desk professionals
-
Anyone who wants command-line security practice
It is especially useful for learners who understand security theory but want more experience asking:
Which command would help me investigate this?
From Command Memorization to Investigation
A common study mistake is learning Windows commands as disconnected definitions.
For example:
tasklist = shows processes
netstat = shows connections
schtasks = shows scheduled tasks
That is useful, but incomplete.
A better way is:
Suspicious execution? → tasklist
Suspicious network activity? → netstat
Unauthorized account? → net user
Privilege escalation? → whoami /priv
Persistence? → schtasks / startup
That turns commands into investigation tools instead of flashcards.
Start Practicing
Windows endpoint investigation does not begin with a perfect alert telling you exactly what happened.
You usually need to collect evidence from different parts of the system and connect it yourself.
The CertInstructor Windows Security Terminal Lab lets you practice that process directly in your browser.
Start here:
https://go.certinstructor.org/labs/windows-terminal-lab/
Work through all 8 security missions and investigate:
-
Malicious processes
-
Attacker connections
-
Backdoor accounts
-
Dangerous privileges
-
Scheduled task persistence
-
Hacking tools
-
C2 communication
-
Startup persistence
No VM or installation is required.
Open the terminal and begin investigating.
CertInstructor — Learn · Practice · Certify
Explore more cybersecurity learning resources:
0 comentarios