Sysinternals

Sysinternals is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Registry Explorer, Event Log Explorer, AppCompatCachParser, VirusTotal, Web Cache View, FTK Imager, Autopsy, Execution, Command and Control, Impact.

Learning Objectives

Conduct endpoint forensic analysis to detect, analyze, and understand malware infections using disk images, registry artifacts, and threat intelligence.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Execution, Command and Control, Impact.

Tools: Registry Explorer, Event Log Explorer, AppCompatCachParser, VirusTotal, Web Cache View, FTK Imager, Autopsy.

Difficulty: medium.