ActiveMQ - LockBit Ransomware

ActiveMQ - LockBit Ransomware is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration, Impact.

Learning Objectives

Reconstruct a full-chain ransomware attack that began with a single CVE in the DMZ and ended with domain-wide compromise, data exfiltration, and encrypted file servers.

Categories: Threat Hunting.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control, Exfiltration, Impact.

Tools: Splunk.

Difficulty: medium.