NetSupport RAT - TA569 is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, Initial Access, Execution, Persistence, Privilege Escalation, Stealth, Credential Access, Discovery, Lateral Movement, Collection.
Learning Objectives
Reconstruct a sophisticated attack timeline by analyzing Windows logs, network traffic, and disk artifacts to identify initial access, persistence, and data exfiltration using Splunk and forensic tools.