Gh0stNet Intrusion

Gh0stNet Intrusion is a blue team lab that falls under the Threat Hunting, Endpoint Forensics categories and will cover the following subjects: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.

Learning Objectives

Synthesize forensic evidence from disk images, PCAP, and Splunk logs to reconstruct a Gh0stNet intrusion, identifying C2, persistence, and data exfiltration via DNS tunneling.

Categories: Threat Hunting, Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.

Tools: CyberChef, FTK Imager, Registry Explorer/RECmd, Wireshark, Registry Explorer, PECmd, CFF Explorer, FLOSS/Strings, Splunk, pe-sieve, Ghidra, IDA.

Difficulty: hard.