Free Windows Security Terminal Lab

Free Windows Security Terminal Lab

Free Windows Security Terminal Lab: Practice Endpoint Investigation from the Command Line

Windows systems generate a huge amount of useful security information.

Running processes, network connections, user accounts, scheduled tasks, startup programs, privileges, and files can all provide evidence during a security investigation.

But knowing that this information exists is different from knowing how to find it.

The CertInstructor Windows Security Terminal Lab is a free browser-based training environment designed to help learners practice Windows security investigation directly from a simulated command line.

Launch the lab:
https://go.certinstructor.org/labs/windows-terminal-lab/

The lab contains 8 investigation missions covering suspicious processes, attacker connections, backdoor accounts, privilege escalation, persistence, hacking tools, command-and-control traffic, and startup mechanisms.

No Windows virtual machine or software installation is required.

Everything runs safely inside your browser.

What Is the Windows Security Terminal Lab?

The Windows Security Terminal Lab puts you in front of a simulated Windows command prompt and asks you to investigate a potentially compromised workstation.

Instead of simply reading descriptions of Windows commands, you use them to answer real investigative questions.

For example:

What process looks malicious?

Which external IP is communicating with the system?

Did the attacker create a new user?

Is there a suspicious scheduled task?

Was malware configured to run automatically?

The training workflow is simple:

Question → Command → Output → Evidence → Answer

This makes the lab useful for learners who want to understand how command-line tools can support security operations and incident response.

Mission 1: Find the Malicious Process

The first mission begins with process investigation.

Try:

tasklist

or the PowerShell equivalent:

Get-Process

The output shows processes running on the simulated workstation.

Your task is to identify a process that does not belong.

This exercise teaches an important endpoint-investigation skill:

Attackers often try to look legitimate.

Malware may use a filename that resembles a Windows process.

For example, legitimate Windows processes include names such as:

svchost.exe

csrss.exe

lsass.exe

A malicious executable may attempt to imitate one of these while adding an unusual suffix or modification.

Do not simply search for a filename that looks obviously malicious.

Compare suspicious names with what legitimate Windows processes normally look like.

Mission 2: Detect the Attacker Connection

Once a suspicious process has been identified, investigate its network activity.

Try:

netstat -ano

or:

Get-NetTCPConnection

These commands allow you to inspect active TCP connections.

Pay attention to:

  • Local IP addresses

  • Local ports

  • Remote IP addresses

  • Remote ports

  • Connection state

  • Process IDs

The key skill is correlation.

If you found a suspicious process in Mission 1, determine whether the same process ID appears in an unusual network connection.

This produces stronger evidence:

Suspicious process + suspicious outbound connection

is more meaningful than either observation alone.

Understanding Process IDs

A process ID, or PID, allows you to connect different types of endpoint evidence.

Suppose tasklist shows:

SuspiciousProcess.exe → PID 14320

and netstat -ano shows:

PID 14320 → External IP → Port 4444

Now you can connect the process to its network activity.

This is an important investigation habit:

Do not treat command output as isolated information. Correlate it.

Mission 3: Find the Backdoor User Account

Attackers may create additional accounts to maintain access to a compromised system.

Use:

net user

to list local user accounts.

Look for anything unexpected.

A suspicious account might:

  • Have an unusual name

  • Have been created recently

  • Belong to the Administrators group

  • Have password expiration disabled

  • Be associated with unusual logon activity

You can investigate a specific account using:

net user <username>

Another useful command is:

net localgroup administrators

This allows you to check which users have local administrative privileges.

The important question is not simply:

Does this username look strange?

Instead ask:

Does this account make sense on this workstation?

Mission 4: Check Privilege Escalation

The next mission focuses on Windows privileges.

Run:

whoami /priv

Windows privileges control what actions a user or process is allowed to perform.

Some privileges deserve particular attention during an incident investigation.

For example, SeDebugPrivilege can allow a process to interact with or debug other processes.

In the wrong context, powerful privileges can help an attacker access sensitive processes or credentials.

Other privileges may also deserve attention depending on the situation.

The lesson is broader than memorizing one privilege name:

Excessive privileges increase the potential impact of a compromise.

This connects directly to the principle of least privilege.

Mission 5: Investigate Scheduled Task Persistence

An attacker does not always want to execute malware only once.

They may want the malware to return after reboot or user logon.

One common persistence mechanism is a scheduled task.

Try:

schtasks

Review the scheduled tasks carefully.

Look for:

  • Unexpected names

  • Tasks created at unusual times

  • Commands launching unknown executables

  • Programs stored in user-writable directories

  • Tasks pretending to be Windows update or maintenance components

The challenge is distinguishing legitimate system activity from something designed to blend in.

Persistence investigation asks:

How does the attacker make sure access survives?

Mission 6: Find Hacking Tools

Attackers may download utilities after compromising a workstation.

Inspect the user's Downloads directory:

dir c:\users\admin\downloads

You may encounter recognizable security or post-exploitation tools.

For example, Mimikatz is widely associated with credential-access activity, while tools such as Netcat can be used for legitimate administration but may also appear in attacker workflows.

Context matters.

A security tool existing somewhere on a computer does not automatically prove compromise.

But a credential-dumping utility suddenly appearing during the same time window as suspicious accounts, malware, and network connections is highly relevant evidence.

This is another reason timeline correlation matters.

Mission 7: Detect Command-and-Control Activity

An attacker may maintain communication with malware through command-and-control infrastructure, often abbreviated as C2.

Use commands such as:

netstat -b

or:

Get-NetTCPConnection

to examine active communication.

The simulated workstation may contain ordinary connections to legitimate services alongside suspicious connections.

Your task is to identify which communication deserves investigation.

Useful questions include:

Is the destination expected?

Which process owns the connection?

Which port is being used?

Does the same destination appear repeatedly?

Does the traffic correlate with a suspicious process?

Attackers may also use ports commonly associated with encrypted web traffic in an attempt to blend into normal network activity.

Therefore:

Common port ≠ automatically legitimate traffic

Context is essential.

Mission 8: Check Startup Persistence

The final mission focuses on programs configured to start automatically.

Try:

wmic startup list

Startup mechanisms are attractive to attackers because they can cause malware to execute whenever a user logs in or the machine starts.

Look for:

  • Unknown executables

  • Strange paths

  • User-profile directories

  • Fake software-update names

  • Programs that correlate with malware discovered earlier

This reinforces another useful incident-response concept:

Attackers often establish more than one persistence mechanism.

For example, the same incident may involve both:

Scheduled Task Persistence

and:

Startup Registry Persistence

Finding one mechanism does not necessarily mean you have found them all.

Useful Commands in the Lab

The simulated terminal supports a range of Windows investigation commands.

System and Network Information

ipconfig

ipconfig /all

hostname

systeminfo

These commands help establish basic context about the workstation.

Identity and Privileges

whoami

whoami /priv

net user

net localgroup administrators

These help you understand which accounts and privileges exist.

Process Investigation

tasklist

Get-Process

These commands help identify running processes and suspicious executables.

Network Investigation

netstat -ano

netstat -b

Get-NetTCPConnection

These help connect processes to network communication.

Persistence Investigation

schtasks

wmic startup list

These can reveal scheduled and startup execution mechanisms.

File Investigation

dir

and directory-specific variations allow you to inspect suspicious files and downloaded tools.

The important goal is not to memorize every command.

Think in terms of investigative questions:

What is running? → tasklist

Who is connected? → netstat

Which accounts exist? → net user

What privileges are enabled? → whoami /priv

What survives reboot? → schtasks / startup entries

This makes the commands much easier to remember.

Use the Suggested Command

Each mission includes a suggested command.

If you are still learning Windows security commands, use it as a starting point.

For example:

Mission: Find the malicious process

Suggested command: tasklist

Run the command.

Read the output.

Then try to determine why one entry deserves attention.

The lab also includes Copy Suggested Command, making it easy to copy the command for study notes.

As you become more comfortable, try solving each mission without relying on the suggestion.

Use Suspicious Highlighting Carefully

The lab includes a Toggle Suspicious Highlight function.

This can help beginners identify potentially important output.

But do not depend on it permanently.

A better progression is:

First attempt: Use highlighting when needed.

Second attempt: Investigate without highlighting.

Later attempts: Explain exactly why the suspicious line matters.

The goal is to move from assisted recognition toward independent analysis.

Use Hints as a Learning Tool

Hints are available when you become stuck.

Try this sequence first:

  1. Read the mission.

  2. Decide which system information you need.

  3. Choose a command.

  4. Examine the output.

  5. Form a hypothesis.

  6. Submit the answer.

  7. Use a hint only if necessary.

This encourages active investigation rather than answer memorization.

Randomized Threat Data

One useful feature of the lab is that several incident indicators can vary between sessions.

Examples may include:

  • Attacker IP

  • C2 IP

  • Malware filename

  • Malware PID

  • Backdoor username

  • Internal workstation address

  • Hostname

  • Suspicious port

This means the learning objective is not:

Remember the answer from last time.

Instead:

Learn how to find the answer.

That distinction is extremely important for practical cybersecurity training.

Progress Is Saved

Your progress can be retained locally in your browser.

The lab remembers information such as:

  • Current mission

  • Score

  • Completed missions

  • Hints

  • Command history

  • Current answer

  • Incident dataset

If you reload the page during an investigation, the simulated attacker data does not suddenly change underneath you.

When you want a fresh case, use RESET.

This clears the current progress and allows the lab to generate a new incident dataset.

Build an Investigation Workflow

By the time you complete all eight missions, you will have practiced several stages of endpoint investigation.

A simplified workflow looks like this:

1. Establish system context

Check hostname, network configuration, user identity, and system information.

2. Inspect processes

Look for unusual execution.

3. Examine network connections

Determine which processes are communicating externally.

4. Investigate accounts

Look for unauthorized users and privilege changes.

5. Examine privileges

Identify dangerous or unnecessary permissions.

6. Look for persistence

Check scheduled tasks and startup mechanisms.

7. Inspect suspicious files and tools

Look for post-exploitation artifacts.

8. Identify C2 communication

Determine whether the host is communicating with attacker-controlled infrastructure.

This can be summarized as:

Process → Network → Accounts → Privileges → Persistence → Tools → C2

Think in Relationships, Not Individual Commands

One of the most valuable habits in security investigation is connecting evidence.

Consider this sequence:

tasklist

reveals a suspicious executable.

Then:

netstat -ano

shows the same PID connecting to an external system.

Then:

net user

reveals a recently created administrator account.

Then:

schtasks

shows a task configured to relaunch the suspicious executable.

Then:

wmic startup list

reveals another persistence mechanism.

Now you no longer have isolated suspicious events.

You have an incident story.

This is exactly what security analysis should aim to produce.

Useful for Certification Preparation

The lab can complement learning for certifications that include topics such as:

  • Windows security

  • Incident response

  • Endpoint investigation

  • Privilege escalation

  • Persistence

  • Network connections

  • Command-and-control

  • Credential access

  • Security operations

The scenarios are especially relevant to learners preparing for certifications such as:

  • CompTIA Security+

  • CompTIA CySA+

  • CompTIA PenTest+

  • CHFI

  • CEH

The lab is not intended to reproduce an entire certification exam.

Its purpose is to help make security concepts more concrete through interaction.

How This Lab Differs From the Windows IR Simulator

The two Windows labs are related, but they serve different purposes.

Windows Security Terminal Lab

Focuses on:

Command → Output → Indicator

You practice investigating Windows using terminal commands across eight focused missions.

Windows Incident Response Simulator

Focuses on:

Incident → Evidence → Timeline → Attack Chain → Root Cause

It is a larger story-driven case investigation.

A useful progression is therefore:

Windows Terminal Lab

Learn the individual investigative tools.

↓

Windows IR Simulator

Use those ideas to reconstruct a complete compromise.

This makes the two apps complementary rather than redundant.

Who Is This Lab For?

The Windows Security Terminal Lab is suitable for:

  • Cybersecurity students

  • SOC analyst learners

  • Incident response beginners

  • Blue-team students

  • Windows administrators moving into security

  • Digital forensics learners

  • Certification candidates

  • Help desk professionals

  • Anyone who wants command-line security practice

It is especially useful for learners who understand security theory but want more experience asking:

Which command would help me investigate this?

From Command Memorization to Investigation

A common study mistake is learning Windows commands as disconnected definitions.

For example:

tasklist = shows processes

netstat = shows connections

schtasks = shows scheduled tasks

That is useful, but incomplete.

A better way is:

Suspicious execution? → tasklist

Suspicious network activity? → netstat

Unauthorized account? → net user

Privilege escalation? → whoami /priv

Persistence? → schtasks / startup

That turns commands into investigation tools instead of flashcards.

Start Practicing

Windows endpoint investigation does not begin with a perfect alert telling you exactly what happened.

You usually need to collect evidence from different parts of the system and connect it yourself.

The CertInstructor Windows Security Terminal Lab lets you practice that process directly in your browser.

Start here:

https://go.certinstructor.org/labs/windows-terminal-lab/

Work through all 8 security missions and investigate:

  • Malicious processes

  • Attacker connections

  • Backdoor accounts

  • Dangerous privileges

  • Scheduled task persistence

  • Hacking tools

  • C2 communication

  • Startup persistence

No VM or installation is required.

Open the terminal and begin investigating.

CertInstructor — Learn · Practice · Certify

Explore more cybersecurity learning resources:

https://certinstructor.org

0 comentarios

Dejar un comentario

Ten en cuenta que los comentarios deben aprobarse antes de que se publiquen.