RansomedTrust - Lynx is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, ANY.RUN, Tria.ge, VirusTotal, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Impact.
Investigate a multi-stage LYNX ransomware intrusion across two trusted Active Directory forests in Splunk, then statically analyze the recovered binary to surface developer artifacts and the embedded victim-contact infrastructure.
Categories: Threat Hunting.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Impact.
Tools: Splunk, ANY.RUN, Tria.ge, VirusTotal.
Difficulty: hard.