BlackEnergy

BlackEnergy is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Volatility, Privilege Escalation, Defense Evasion.

Learning Objectives

Develop practical skills in Windows memory forensics using Volatility by detecting malware indicators, analyzing suspicious processes, and identifying code injection and unauthorized DLLs in a compromised system.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Privilege Escalation, Defense Evasion.

Tools: Volatility.

Difficulty: medium.