EscapeRoom is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, NetworkMiner, Brim, UPX, IDA, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Command and Control.
Reconstruct a multi-stage attack by analyzing network traffic, cracking credentials, and reverse engineering malware using Wireshark, John the Ripper, and IDA Pro to identify persistence and C2 commands.
Categories: Network Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Command and Control.
Tools: Wireshark, NetworkMiner, Brim, UPX, IDA.
Difficulty: medium.