Gh0stNet Intrusion

Gh0stNet Intrusion is a blue team lab that falls under the Threat Hunting, Endpoint Forensics categories and will cover the following subjects: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.

Learning Objectives

Synthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

Categories: Threat Hunting, Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.

Tools: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA.

Difficulty: hard.