GhostConnect - TA583 is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: VirusTotal, Splunk, Initial Access, Execution, Discovery, Collection.
Hunt Sysmon process trees, Chrome browsing artifacts, and Mark-of-the-Web streams to rebuild a the full kill chain from phishing delivery through AD enumeration to HTTPS exfiltration.
Categories: Threat Hunting.
MITRE ATT&CK Tactics: Initial Access, Execution, Discovery, Collection.
Tools: VirusTotal, Splunk.
Difficulty: easy.