PacketMaze

PacketMaze is a blue team lab that falls under the Network Forensics category and will cover the following subjects: Wireshark, Brim, NetworkMiner, suricatarunner, suricata.rules, MAC lookup, Initial Access.

Learning Objectives

Analyze network traffic using Wireshark to identify suspicious activity, extract IOCs, and uncover authentication details, file transfers, and server information across multiple protocols.

Categories: Network Forensics.

MITRE ATT&CK Tactics: Initial Access.

Tools: Brim, suricatarunner, suricata.rules, NetworkMiner, Wireshark, MAC lookup.

Difficulty: medium.