Fork Bomb - TeamPCP is a blue team lab that falls under the Threat Intel, Endpoint Forensics categories and will cover the following subjects: CyberChef, Notepad++, Sysmon, Google Search, Initial Access, Persistence, Privilege Escalation, Discovery, Collection, Command and Control, Impact.
Investigate a real-world supply chain attack from first alert to threat actor attribution — and find out how a single Python package nearly handed over the keys to an entire cloud environment.
Categories: Threat Intel, Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Persistence, Privilege Escalation, Discovery, Collection, Command and Control, Impact.
Tools: CyberChef, Notepad++, Sysmon, Google Search.
Difficulty: easy.