Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-MAL-LAB-003Medium
Browser LabLD-MAL-LAB-003Medium28 min

From Behavior to Detection

You have finished detonating a confirmed-malicious Badr sample and captured its behavior report and network trace. Now turn the analysis into defensive value: extract the durable IOCs, map the behavior to ATT&CK, and choose the behavior worth handing to detection engineering. Prefer what survives infrastructure rotation.

What you will be able to do

  • Extract host and network IOCs with confidence.
  • Map observed behavior to ATT&CK techniques.
  • Select the most durable behavior for detection.
IOC AnalysisDetection EngineeringNetwork AnalysisT1059.001PowerShellT1055Process InjectionT1003.001LSASS MemoryT1071.001Web Protocols

Sign in to start this lab.

Sign in