Ancientland Breach - LockBit

Ancientland Breach - LockBit is a blue team lab that falls under the Network Forensics, Endpoint Forensics categories and will cover the following subjects: hayabusa, CyberChef, VirusTotal, Wireshark, IDA, MFTECmd, Timeline Explorer, Volatility 3, Impacket, Initial Access, Execution, Persistence, Privilege Escalation, Credential Access, Command and Control, Exfiltration.

Learning Objectives

Trace a real-world attack chain end to end — from a leaked VPN config to domain-wide ransomware. Along the way you will decode obfuscated malware, reverse-engineer a kernel exploit, crack beacon encryption, and reconstruct the attacker's every move from disk, memory, and network artifacts.

Categories: Network Forensics, Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Credential Access, Command and Control, Exfiltration.

Tools: hayabusa, CyberChef, VirusTotal, Wireshark, IDA, MFTECmd, Timeline Explorer, Volatility 3, Impacket.

Difficulty: hard.