WebLogic is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: CobaltStrikeParser, Initial Access, Execution, Persistence, Privilege Escalation, Command and Control, Exfiltration.
Reconstruct a WebLogic server attack timeline by analyzing memory dumps MemProcFS output to identify initial access, persistence, C2, and data exfiltration IOCs.
Categories: Endpoint Forensics.
MITRE ATT&CK Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Command and Control, Exfiltration.
Tools: CobaltStrikeParser.
Difficulty: medium.