Malware Traffic Analysis 1 is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Brim, suricatarunner, suricata.rules, NetworkMiner, Wireshark, Initial Access, Execution, Command and Control.
Analyze network traffic using Wireshark to identify an infected host, trace an exploit kit infection chain, and extract malicious URLs and file hashes.
Categories: Network Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Command and Control.
Tools: Brim, suricatarunner, suricata.rules, NetworkMiner, Wireshark.
Difficulty: medium.