HireMe

HireMe is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Registry Explorer, LECmd, Autopsy, FTK Imager, RegRipper, OST Viewer, Execution, Credential Access, Discovery, Command and Control.

Learning Objectives

Analyze a disk image to investigate multiple forensic cases by examining registry, event logs, and email artifacts using specified forensic tools.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Execution, Credential Access, Discovery, Command and Control.

Tools: FTK Imager, Autopsy, Registry Explorer, LECmd, RegRipper, OST Viewer.

Difficulty: medium.