Brutal Tank

Brutal Tank is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Wireshark, Arkime, Reconnaissance, Execution, Credential Access, Discovery, Command and Control, Impact.

Learning Objectives

Reconstruct an ICS attack chain by analyzing network traffic with Arkime and Wireshark to identify PLC compromise, I/O manipulation, and classify techniques using MITRE ATT&CK for ICS.

Categories: Threat Hunting.

MITRE ATT&CK Tactics: Reconnaissance, Execution, Credential Access, Discovery, Command and Control, Impact.

Tools: Arkime, Wireshark.

Difficulty: hard.