M3HT4-001 THE WEB GATE INTERACTIVE REPLAY

Linux Web Service Intrusion Contained before exfiltration.

A realistic, bounded intrusion storyline that begins with a historical web vulnerability, progresses through post-exploitation discovery and collection, and is contained when the represented command-and-control channel is blocked before exfiltration.

PLATFORM Linux FOCUS Web intrusion LEVEL Intermediate PUBLIC MODE Synthetic / sanitized
Linux Web Service Intrusion scenario artwork
SELECTED SCENARIO M3HT4-001 · Linux Web Service Intrusion Interactive Blue / Red / Purple replay
Back to scenario library
M3HT4-001-BETA 01 / 01

Linux Web Service Intrusion

A realistic, bounded intrusion storyline that begins with a historical web vulnerability, progresses through post-exploitation discovery and collection, and is contained when the represented command-and-control channel is blocked before exfiltration.

VULNERABILITY CONTEXT CVE-2021-41773 Apache HTTP Server 2.4.49 Critical · CVSS 3.1 9.8 · High-level context only · exploit procedure not published ↗
ATTACK PATH
Initial Access Execution Discovery Collection Command & Control Contained
ENVIRONMENT Disposable Linux web-service scenario
DURATION 04:00
DATA Synthetic public replay
EXPERIENCE DEPTH
Start focused. Go deeper when you want.

Guided mode keeps the current event, selected team lens, and next decision in focus.

ANALYSIS LENS

Same evidence. Different operational perspective.

INTERACTIVE REPLAY

Scenario timeline

READY
ATTACK PATH

ATT&CK-mapped storyline

Completed Current Outcome
PRE-FLIGHT Scenario preparation The mapped attack path begins with the first adversary behavior.
READY

Select a stage to jump to its first event. Discovery and other multi-event stages unfold as you continue the storyline.

00:00 / 04:00
01 / 12 PLATFORM EVENT
00:00 Scenario initialized No ATT&CK mapping
CURRENT MOMENT

Scenario initialized

EVENT 01 / 12 PLATFORM EVENT

◈
BLUE LENS Defensive interpretation

KEY TAKEAWAYS Two essentials first. Expand the workbench when you want the full operational detail.
VERIFY

INTERPRET

DECIDE

ACTION

i
Public preview boundary

This beta is a static client-side simulation. It cannot execute commands, accept uploads, access the private M3HT4 lab, reach management interfaces, or retrieve live telemetry. The network example uses the documentation-only TEST-NET-2 address range.

Read the M3HT4 Responsible Use & Research Policy →
M3HT4 MODERN HUNTING TERRAIN
INDEPENDENT PROJECT SUPPORT

Keep the terrain
moving.

Voluntary support helps fund the infrastructure, research, tooling, and public learning experiences behind M3HT4.

Research Tools Infrastructure

Support never buys access. It does not purchase influence, services, testing authorization, priority, or private M3HT4 material.

SUPPORT M3HT4

Choose what feels right.

Ko-fi checkout
Opening secure support panel Loading Ko-fi only after you choose Support.

Checkout is provided by Ko-fi and its payment partners. M3HT4 does not collect payment-card details through this website.