Seized is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: Volatility, CyberChef, grep, Execution, Persistence, Privilege Escalation, Stealth, Command and Control.
Using Volatility to investigate a Linux compromise, uncovering attacker techniques like persistence, rootkits, and network backdoors, while reinforcing skills in threat hunting and incident response.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth, Command and Control.
Tools: Volatility, CyberChef, grep.
Difficulty: medium.