Maromalix Nightmare

Maromalix Nightmare is a blue team lab that falls under the Threat Hunting, Endpoint Forensics categories and will cover the following subjects: ELK, MFTECmd, Timeline Explorer, JLECmd, RegRipper, Registry Explorer/RECmd, Strings, Impacket, Initial Access, Execution, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control.

Learning Objectives

A deal was stolen before it was ever signed. Someone got in, found exactly what they needed, and vanished. Your job is to prove it.

Categories: Threat Hunting, Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Command and Control.

Tools: ELK, MFTECmd, Timeline Explorer, JLECmd, RegRipper, Registry Explorer/RECmd, Strings, Impacket.

Difficulty: medium.