ResourcePacks is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Notepad++, PECmd, DB Browser for SQLite, Event Log Explorer, MFTECmd, Timeline Explorer, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Discovery, Command and Control.
Reconstruct an attack timeline by analyzing forensic artifacts to identify a UAC bypass, WMI persistence, and backdoor user creation techniques.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Discovery, Command and Control.
Tools: Notepad++, PECmd, DB Browser for SQLite, Event Log Explorer, MFTECmd, Timeline Explorer.
Difficulty: medium.