TOCTOU - OilRig is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: MemProcFS, Volatility 3, Strings, VirusTotal, Timeline Explorer, Execution, Persistence, Privilege Escalation, Stealth.
Correlate memory, registry, and filesystem artifacts using Volatility 3, MemProcFS, and Timeline Explorer to reconstruct a multi-stage attack timeline and map attacker TTPs to MITRE ATT&CK.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Execution, Persistence, Privilege Escalation, Stealth.
Tools: MemProcFS, Volatility 3, Strings, VirusTotal, Timeline Explorer.
Difficulty: hard.