BreakOut-Daedalus

BreakOut-Daedalus is a blue team lab that falls under the Threat Hunting, Endpoint Forensics, Network Forensics categories and will cover the following subjects: Wireshark, Network Miner, Splunk, KAPE, Arsenal Image Mounter, Autopsy, FTK Imager, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.

Learning Objectives

The hosting panel is the new front door; chase an attacker from a forged session all the way to root, breaking out of a container and burrowing into the host along the way. By correlating SIEM telemetry, host disk forensics, and network captures across the full intrusion.

Categories: Threat Hunting, Endpoint Forensics, Network Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration.

Tools: Wireshark, Network Miner, Splunk, KAPE, Arsenal Image Mounter, Autopsy, FTK Imager.

Difficulty: hard.