Web Investigation

Web Investigation is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, Network Miner, Initial Access, Persistence, Command and Control.

Learning Objectives

Examine network traffic with Wireshark to investigate web server compromise, identify SQL injection, extract attacker credentials, and detect uploaded malware.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Initial Access, Persistence, Command and Control.

Tools: Wireshark, Network Miner.

Difficulty: easy.