Hafnium APT is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: ELK, Execution, Privilege Escalation, Stealth, Credential Access.
Correlate Windows Defender, Sysmon, and Security logs in Elastic Stack to reconstruct HafinumAPT's initial access, persistence, and lateral movement TTPs.
Categories: Threat Hunting.
MITRE ATT&CK Tactics: Execution, Privilege Escalation, Stealth, Credential Access.
Tools: ELK.
Difficulty: hard.