Module 18: SIEM Part Two: Combining the Logs
Phase One: Web Server Initial Access
Enumeration and Command Injection of web01
Phase One Detection Rules







Phase Two: Lateral Movement to Application Server
Brute Force and Authentication to appsrv01
Phase Two Detection Rules






Phase Three: Persistence and Privilege Escalation on Application Server
Persistence and Privilege Escalation on appsrv01
Phase Three Detection Rules




Phase Four: Perform Actions on Domain Controller
Dump AD Database
Phase Four Detection Rules


Last updated