Browser LabLD-MAL-LAB-003Medium
Browser LabLD-MAL-LAB-003Medium28 min
From Behavior to Detection
You have finished detonating a confirmed-malicious Badr sample and captured its behavior report and network trace. Now turn the analysis into defensive value: extract the durable IOCs, map the behavior to ATT&CK, and choose the behavior worth handing to detection engineering. Prefer what survives infrastructure rotation.
What you will be able to do
- Extract host and network IOCs with confidence.
- Map observed behavior to ATT&CK techniques.
- Select the most durable behavior for detection.
IOC AnalysisDetection EngineeringNetwork AnalysisT1059.001 — PowerShellT1055 — Process InjectionT1003.001 — LSASS MemoryT1071.001 — Web Protocols
Sign in to start this lab.
Sign in