BPFDoor - StraitsTelecom is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: tshark, ausearch, utmpdump, CyberChef, Wireshark, Ghidra, Strings, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.
Investigate a two-host Linux intrusion using live triage collections and a network capture: analyse authentication, audit and login records, detect a backdoor that never opens a port, statically analyse a stripped ELF implant, and recover data from an encrypted command-and-control channel.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.
Tools: tshark, ausearch, utmpdump, CyberChef, Wireshark, Ghidra, Strings.
Difficulty: medium.