GateBreak is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: FSEParser, Spotlight-Parser, ios_apt, unifiedlog_iterator, plist Editor, CSViewer, Execution, Persistence, Privilege Escalation, Stealth, Collection, Command and Control.
Reconstruct a macOS attack timeline by correlating Unified Logs, FSEvents, and browser artifacts using macMRU.py and unifiedlog_iterator to identify initial access, Gatekeeper bypass, and persistence.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth, Collection, Command and Control.
Tools: CSViewer, FSEParser, Spotlight-Parser, ios_apt, unifiedlog_iterator, plist Editor.
Difficulty: hard.