BPFDoor - StraitsTelecom

BPFDoor - StraitsTelecom is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: tshark, ausearch, utmpdump, CyberChef, Wireshark, Ghidra, Strings, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.

Learning Objectives

Investigate a two-host Linux intrusion using live triage collections and a network capture: analyse authentication, audit and login records, detect a backdoor that never opens a port, statically analyse a stripped ELF implant, and recover data from an encrypted command-and-control channel.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.

Tools: tshark, ausearch, utmpdump, CyberChef, Wireshark, Ghidra, Strings.

Difficulty: medium.