Insider is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: FTK Imager, Execution, Credential Access.
Analyze Linux disk image artifacts, including logs and Bash history, using FTK Imager to investigate insider threat activities and reconstruct user actions.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Credential Access.
Tools: FTK Imager.
Difficulty: easy.