Sysinternals is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Registry Explorer, Event Log Explorer, AppCompatCachParser, VirusTotal, Web Cache View, FTK Imager, Autopsy, Execution, Command and Control, Impact.
Learning Objectives
Conduct endpoint forensic analysis to detect, analyze, and understand malware infections using disk images, registry artifacts, and threat intelligence.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Command and Control, Impact.