Malware Traffic Analysis 3 is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Brim, suricatarunner, suricata.rules, NetworkMiner, Wireshark, GHex, pesec, Initial Access, Stealth, Command and Control.
Synthesize network, binary, and threat intelligence artifacts to reconstruct an exploit kit attack chain, identifying components, deobfuscating payloads, and analyzing binary protections.
Categories: Network Forensics.
MITRE ATT&CK Tactics: Initial Access, Stealth, Command and Control.
Tools: Brim, suricatarunner, suricata.rules, NetworkMiner, Wireshark, GHex, pesec.
Difficulty: medium.