Exfiltrated

Exfiltrated is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: CyberChef, Wayback Machine, Forensic Imaging (mount), Python, Execution, Persistence, Privilege Escalation, Credential Access, Collection, Command and Control, Exfiltration.

Learning Objectives

Reconstruct a Linux intrusion by analyzing forensic images, system logs, and custom scripts to identify brute-force, privilege escalation, persistence, and exfiltrated data.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Credential Access, Collection, Command and Control, Exfiltration.

Tools: Forensic Imaging (mount), Wayback Machine, CyberChef, Python.

Difficulty: medium.