ELPACO-team is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Event Log Explorer, Eric Zimmerman Tools, NTFS Log Tracker, Registry Explorer, Timeline Explorer, Volatility 3, Execution, Persistence, Defense Evasion, Credential Access, Command and Control, Impact.
Learning Objectives
Correlate Sysmon, MFT, and application logs to reconstruct a ransomware attack timeline, identifying persistence, defense evasion, and data exfiltration TTPs.