Penumbra is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Registry Explorer/RECmd, FTK Imager, Autopsy, MFTECmd, Timeline Explorer, EvtxECmd, Text Editor, HexEditor, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Discovery, Collection, Command and Control, Exfiltration.
Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Defense Impairment, Discovery, Collection, Command and Control, Exfiltration.
Tools: DB Browser for SQLite, Registry Explorer/RECmd, FTK Imager, Autopsy, MFTECmd, Timeline Explorer, EvtxECmd, Text Editor, HexEditor.
Difficulty: medium.