Code Blue - APT29 is a blue team lab that falls under the Cloud Forensics category and will cover the following subjects: Microsoft Sentinel, Entra ID Sign-in Logs, Entra ID Audit Logs, Azure Activity Logs, Office 365 Audit Logs, Azure Diagnostics Logs, KQL Query Editor, Initial Access, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection.
Reconstruct a multi-stage APT29 intrusion by analyzing Azure and M365 logs to trace device code phishing, OAuth token abuse, service account chaining, Silver SAML forgery, and PHI exfiltration.
Categories: Cloud Forensics.
MITRE ATT&CK Tactics: Initial Access, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection.
Tools: Microsoft Sentinel, Entra ID Sign-in Logs, Entra ID Audit Logs, Azure Activity Logs, Office 365 Audit Logs, Azure Diagnostics Logs, KQL Query Editor.
Difficulty: hard.