CodeFreeze

CodeFreeze is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: PECmd, Event Viewer, CyberChef, Registry Explorer, DB Browser for SQLlite, Timeline Explorer, Initial Access, Execution, Persistence, Privilege Escalation, Stealth.

Learning Objectives

Reconstruct the complete attack timeline by analyzing browser history, event logs, registry, and Git artifacts to identify initial access, persistence, and data exfiltration mechanisms.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth.

Tools: PECmd, Event Viewer, CyberChef, Registry Explorer, DB Browser for SQLlite, Timeline Explorer.

Difficulty: medium.