KrakenKeylogger

KrakenKeylogger is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Timeline Explorer, LECmd, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Command and Control, Exfiltration.

Learning Objectives

Analyze Windows 10 notification artifacts, installed applications, LNK files, and Applications logs to uncover malicious activity and enhance forensic investigation capabilities.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Command and Control, Exfiltration.

Tools: DB Browser for SQLite, LECmd, Timeline Explorer.

Difficulty: medium.