RoastToRoot

RoastToRoot is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Notepad++, 7zip, JohnTheRipper, Wireshark, Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Collection, Exfiltration.

Learning Objectives

Analyze network traffic to reconstruct a complete domain compromise attack chain, from AS-REP Roasting and Kerberoasting through privilege escalation, lateral movement, and data exfiltration using rclone.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Reconnaissance, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Collection, Exfiltration.

Tools: Notepad++, 7zip, JohnTheRipper, Wireshark.

Difficulty: hard.