Code Blue - APT29 is a blue team lab that falls under the Cloud Forensics category and will cover the following subjects: Microsoft Sentinel, Entra ID Sign-in Logs, Entra ID Audit Logs, Azure Activity Logs, Office 365 Audit Logs, Azure Diagnostics Logs, KQL Query Editor, Initial Access, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection.
Learning Objectives
Reconstruct a multi-stage APT29 intrusion by analyzing Azure and M365 logs to trace device code phishing, OAuth token abuse, service account chaining, Silver SAML forgery, and PHI exfiltration.