MAMuhammad Abdullahinshiplog.hashnode.dev·Aug 5 · 5 min readSOC205 | Malicious Macro Has Been ExecutedPlatform: LetsDefend Date Investigated: February 28, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary A malicious Word document disguised as an invoice was deli00
MAMuhammad Abdullahinshiplog.hashnode.dev·Aug 5 · 4 min readSOC176 | RDP Brute Force DetectedPlatform: LetsDefend Date Investigated: March 07, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary On March 7, 2024 at 11:44 AM, an alert fired after multiple f00
MAMuhammad Abdullahinshiplog.hashnode.dev·Aug 5 · 5 min readSOC338 | Lumma Stealer, DLL Side-Loading via ClickFix PhishingPlatform: LetsDefend Date Investigated: March 13, 2025 Severity: Critical Category: Data Leakage Verdict: True Positive ✅ Actions Taken: Email deleted, endpoint contained Summary A phishing email impe00
MAMuhammad Abdullahinshiplog.hashnode.dev·Jul 28 · 4 min readComing Back to Writing = and My First Cybersecurity ProjectIt's been a while since I've written anything publicly. I used to be fairly active documenting what I was building as a developer, and somewhere along the way - between shipping products and then pivo00
MAMuhammad Abdullahinshiplog.hashnode.dev·Jul 28 · 5 min readSecond Project Back: A Phishing Email Analyzer (Still a Beginner, Still Learning)A little while ago I wrote about coming back to documenting my work after a long quiet stretch, starting with a small IOC enrichment tool. This is the next entry in that same habit — a phishing email 00