ActiveMQ - LockBit Ransomware is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration, Impact.
Reconstruct a full-chain ransomware attack that began with a single CVE in the DMZ and ended with domain-wide compromise, data exfiltration, and encrypted file servers.
Categories: Threat Hunting.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration, Impact.
Tools: Splunk.
Difficulty: medium.