5G Security Operations — SOC for 5G Core Networks · Pro
You will analyze a multi-stage 5GC attack and map it to MITRE FiGHT. The scenario: an adversary compromised a public-facing OAM interface using a known vulnerability; gained initial access to the operator's network; performed reconnaissance to find NF endpoints via NRF discovery; abused service-account credentials to access UDM subscription data; exfiltrated subscriber data over an encrypted channel. The lab walks through identifying which FiGHT tactics and techniques each stage represents, and assesses detection coverage for each.