StarkTech Incident - APT41 is a blue team lab that falls under the Threat Hunting category and will cover the following subjects: Splunk, Initial Access, Execution, Persistence, Privilege Escalation, Defense Impairment, Credential Access, Lateral Movement, Collection, Command and Control, Exfiltration.
Learning Objectives
Reconstruct a multi-stage attack timeline by analyzing Sysmon and Windows event logs in Splunk to identify attacker tactics from initial access to data exfiltration.