l337 S4uc3 is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Volatility, Wireshark, NetworkMiner, Brim, Initial Access, Execution, Stealth, Discovery, Collection.
Analyze network traffic and memory dumps using Wireshark, Zui, and Volatility to investigate a targeted attack, identify Zeus malware, and reconstruct attacker actions.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Stealth, Discovery, Collection.
Tools: Volatility, Wireshark, NetworkMiner, Brim.
Difficulty: medium.