Exfiltrated is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Forensic Imaging (mount), Wayback Machine, CyberChef, Python, Execution, Persistence, Privilege Escalation, Credential Access, Collection, Command and Control, Exfiltration.
Reconstruct a Linux intrusion by analyzing forensic images, system logs, and custom scripts to identify brute-force, privilege escalation, persistence, and exfiltrated data.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Credential Access, Collection, Command and Control, Exfiltration.
Tools: Forensic Imaging (mount), Wayback Machine, CyberChef, Python.
Difficulty: medium.