LockBit is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: KAPE, EZ Tools, Event Log Explorer, Event Viewer, CyberChef, Execution, Persistence, Privilege Escalation, Defense Impairment, Credential Access, Lateral Movement, Impact.
Reconstruct a multi-system LockBit ransomware attack chain by correlating Windows event logs, registry artifacts, and PowerShell activity to identify TTPs.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Defense Impairment, Credential Access, Lateral Movement, Impact.
Tools: KAPE, EZ Tools, Event Log Explorer, Event Viewer, CyberChef.
Difficulty: medium.