Rhadamanthys

Rhadamanthys is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: CyberChef, Eric Zimmerman Tools, Timeline Explorer, Event Log Explorer, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Command and Control.

Learning Objectives

Hunt mail caches, MFT records, and Prefetch to unmask the initial dropper and rebuild the attack timeline.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Command and Control.

Tools: CyberChef, Eric Zimmerman Tools, Timeline Explorer, Event Log Explorer.

Difficulty: medium.