PoisonedCredentials

PoisonedCredentials is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, Credential Access, Collection.

Learning Objectives

Analyze network traffic for LLMNR/NBT-NS poisoning attacks using Wireshark to identify the rogue machine, compromised accounts, and affected systems.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Credential Access, Collection.

Tools: Wireshark.

Difficulty: easy.