ProxyLogon - HAFNIUM

ProxyLogon - HAFNIUM is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: GrayLog, Reconnaissance, Initial Access, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Lateral Movement.

Learning Objectives

Investigate SIEM logs using GrayLog to identify indicators of compromise associated with the ProxyLogon vulnerability (CVE-2021-26855).

Categories: Threat Hunting.

MITRE ATT&CK Tactics: Reconnaissance, Initial Access, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Lateral Movement.

Tools: GrayLog.

Difficulty: hard.