BankingTroubles

BankingTroubles is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: PDF-Tools, Malfind, libemu, Volatility, Strings, Foremost, Hexdump, Firebug, Objdump, Initial Access, Execution, Defense Evasion, Command and Control, Impact.

Learning Objectives

Evaluate a memory image using Volatility and forensic tools to reconstruct the attack chain initiated by a malicious PDF with JavaScript.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Defense Evasion, Command and Control, Impact.

Tools: PDF-Tools, Malfind, libemu, Volatility, Strings, Foremost, Hexdump, Firebug, Objdump.

Difficulty: hard.