MITRE TryHackme Write-Up
TASK 1 & 2 are simple click and complete tasks
TASK 3
Question 1: Only blue teamers will use the ATT&CK Matrix? (Yay/Nay)
Nay
Question 2: What is the ID for this technique?
T1566
Question 3: Based on this technique, what mitigation covers identifying social engineering techniques?
User Training
Question 4: There are other possible areas for detection for this technique, which occurs after what other technique?
User Execution
Question 5: What group has used spear phishing in their campaigns?
Dragonfly
Question 6: Based on the information for this group, what are their associated groups?
TG-4192, Crouching Yeti, IRON LIBERTY, Energetic Bear
Question 7: What tool is attributed to this group to transfer tools or files from one host to another within a compromised environment?
PsExec
Question 8: Based on the information about this tool, what group used a customized version of it?
FIN5
Question 9: This group has been active since what year?
2008
Question 10:Instead of Mimikatz, what OS Credential Dumping tool is does this group use?
Windows Credential Editor