Formbook

Formbook is a blue team lab that falls under the Malware Analysis, Endpoint Forensics categories and will cover the following subjects: PowerShell, Notepad++, Event Log Explorer, CyberChef, DB Browser for SQLite, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Command and Control.

Learning Objectives

Trace the attack chain from phishing delivery through obfuscated JavaScript, PowerShell loaders, and final payload execution.

Categories: Malware Analysis, Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Command and Control.

Tools: PowerShell, Notepad++, Event Log Explorer, CyberChef, DB Browser for SQLite.

Difficulty: hard.