BYOD Breach is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: CyberChef, Windows Event Viewer, JADX, abx2xml, Resource Development, Initial Access, Execution, Privilege Escalation, Stealth, Command and Control, Exfiltration.
Correlate Android and Windows forensic artifacts, including logs and malware analysis, to reconstruct a multi-stage BYOD breach from initial access to persistence.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Resource Development, Initial Access, Execution, Privilege Escalation, Stealth, Command and Control, Exfiltration.
Tools: CyberChef, Windows Event Viewer, JADX, abx2xml.
Difficulty: medium.