PacketDetective

PacketDetective is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, Execution, Defense Evasion, Command and Control.

Learning Objectives

Analyze network traffic in PCAP files using Wireshark to extract IOCs and reconstruct attacker tactics like authentication and remote execution.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Execution, Defense Evasion, Command and Control.

Tools: Wireshark.

Difficulty: easy.