REvil - GOLD SOUTHFIELD is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, ELK, OSINT, Execution, Privilege Escalation, Stealth, Discovery.
Learning Objectives
Analyze Sysmon logs in Elastic SIEM to investigate REvil ransomware attack behaviors, decode recovery sabotage commands, and identify IOCs including the C2 onion domain.