Lockdown

Lockdown is a blue team lab that falls under the Network Forensics category and will cover the following subjects: FLOSS/Strings, Wireshark, Threat Intel tools, MemProcFS, Volatility 3, Execution, Persistence, Privilege Escalation, Stealth, Discovery, Lateral Movement, Command and Control.

Learning Objectives

Reconstruct a multi-stage intrusion by analyzing network traffic, memory, and malware artifacts using Wireshark, Volatility, and VirusTotal, mapping findings to MITRE ATT&CK.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth, Discovery, Lateral Movement, Command and Control.

Tools: FLOSS/Strings, Wireshark, Threat Intel tools, MemProcFS, Volatility 3.

Difficulty: easy.