> LAB_ENVIRONMENT

RAT has been setup in one of the machines connected to the network to steal sensitive corporate documents located on the Desktop of a server. Further investigation revealed the IP address of the server: 20.20.10.26.
ATTACKER MACHINE INTERFACE 10.10.5.50
☠️ THIEF CLIENT v2.4 (RAT CONTROLLER)
Thief Client initialized. Waiting for connection parameters...
--- Contents of C:\Users\Admin\Desktop ---
📄 file1.docx
📕 report.pdf
📝 creds.txt
--- End of directory (3 items found) ---
>_

> ASSESSMENT

Determine the number of files present in the Desktop folder.
Hint: Thief tool is located at Z:\CCT-Tools\CCT Module 01 Information Security Threats and Vulnerabilities\Remote Access Trojans (RAT)\Thief
Explanation:
After establishing a connection to 20.20.10.26 using the Thief Client, the Desktop directory reveals exactly 3 files: file1.docx, report.pdf, and creds.txt. Therefore, the correct answer is C.