Penumbra
Penumbra is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Registry Explorer/RECmd, FTK Imager, Autopsy, MFTECmd, Timeline Explorer, EvtxECmd, Text Editor, HexEditor, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Discovery, Collection, Command and Control, Exfiltration.
Learning Objectives
Synthesize diverse forensic artifacts including $MFT, USN journal, and registry hives to reconstruct an anti-forensic intrusion timeline from initial access to exfiltration.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Discovery, Collection, Command and Control, Exfiltration.
Tools: DB Browser for SQLite, Registry Explorer/RECmd, FTK Imager, Autopsy, MFTECmd, Timeline Explorer, EvtxECmd, Text Editor, HexEditor.
Difficulty: medium.