VaultBreak is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: PECmd, Event Log Explorer, Event Viewer, CyberChef, Notepad++, MFTECmd, Timeline Explorer, Reconnaissance, Execution, Persistence, Privilege Escalation, Defense Evasion, Command and Control.
Learning Objectives
Reconstruct a multi-stage attack by analyzing Sysmon, WMI, and Prefetch logs to identify initial infection, advanced persistence, and C2 communications.