Gh0stNet Intrusion
Gh0stNet Intrusion is a blue team lab that falls under the Threat Hunting, Endpoint Forensics categories and will cover the following subjects: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.
Learning Objectives
Synthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.
Categories: Threat Hunting, Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.
Tools: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA.
Difficulty: hard.