m1n347
Has successfully completed 🎉
TeamSpy Lab
Instructions:Uncompress the lab (pass:Â cyberdefenders.org)Scenario:An employee reported that his machine started to act strangely after receiving a suspicious email with a document file. The incident response team captured a couple of memory dumps from the suspected machines for further inspection. As a soc analyst, analyze the dumps and help the IR team figure out what happened!Resources:Analyzing MS Office Malware with OfficeMalScanner (reconstructer.org)Volatility Command Reference (GitHub wiki)
Read More