WireDive

WireDive is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, Brim, Initial Access, Execution, Persistence, Lateral Movement, Collection, Command and Control, Exfiltration.

Learning Objectives

Analyze diverse network traffic using Wireshark to decrypt HTTPS, identify protocol misconfigurations, and extract critical network and system forensic artifacts.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Lateral Movement, Collection, Command and Control, Exfiltration.

Tools: Brim, Wireshark.

Difficulty: medium.