TheTruth

TheTruth is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Strings, Autopsy, JADX, Resource Development, Execution, Collection, Exfiltration.

Learning Objectives

Reconstruct an Android attack timeline using forensic artifacts to identify RatMilad malware, extract its C2, and attribute a fraudulent transaction.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Resource Development, Execution, Collection, Exfiltration.

Tools: Autopsy, JADX, Strings, DB Browser for SQLite.

Difficulty: medium.