TLTirthak Likharintirthaklikhar.hashnode.dev·4d ago · 6 min readWhat EDR Reveals After a Suspicious Document OpensWhen a Word document launches a command shell and that shell retrieves an executable, there is already a sequence worth investigating. The next question is how far it went. A downloaded file and a run00
TLTirthak Likharintirthaklikhar.hashnode.dev·Sep 11 · 22 min readClimbing the Pyramid of Pain: From Hashes to TTP-Based DetectionAuthor's note: This article explains the defensive reasoning and security concepts behind the TryHackMe Summit room. It deliberately omits flags and is not intended to be an answer guide. A security 00
TLTirthak Likharintirthaklikhar.hashnode.dev·May 31 · 12 min readSOC Team Internals: How an L1 Analyst Thinks, Triages and ReportsI spent the last few weeks going through the TryHackMe SOC Team Internals module. Four rooms. Around four hours of actual learning. And a lot of things clicked that I had been reading about in theory 00
TLTirthak Likharintirthaklikhar.hashnode.dev·May 25 · 9 min readWhy the OSI Model Diagram in Your Textbook Is IncompleteI spent weeks staring at the OSI model and the Ethernet frame diagram in my notebook. I could label every field. I could recite all seven layers. But I genuinely had no idea what was actually happenin10
TLTirthak Likharintirthaklikhar.hashnode.dev·May 7 · 11 min readTryHackMe SEC1 Certification: A Honest, Detailed ReviewSEC1 is one of the few beginner certifications that actually puts you inside a real environment and asks you to work. This is a first-hand account of what the exam looks like, where it tests you hard,00