SSSunny Sainiinvillxn.hashnode.dev·36m ago · 29 min readCase File #1: Preparing the Crime SceneHello, Analysts and Attackers 👋 I'm Sunny - I love spending my time into breaking things, figuring out how they work, and then learning how to detect them. Welcome to our series "The Detection Engine00
HSHemant Sharmainhemant-cybersec.hashnode.dev·16h ago · 8 min readMastering Windows Host Security & Active Directory Mechanics: A SOC Analyst's Defensive Guide📌 Introduction In modern enterprise environments, Microsoft Windows and Active Directory (AD) form the core identity and endpoint infrastructure. For Security Operations Center (SOC) analysts, monito00
KDKajal Dhanjalinkajalbuilds.hashnode.dev·Jul 21 · 14 min readFortiBleed had around twenty people. JadePuffer had an agent. The way in was identical.The thesis I had to throw out Two intrusions dominated the last month, and the coverage of both led with AI. FortiBleed: an initial-access operation running on around twenty people with a defined div00
EEEa Etin0xnull-security.hashnode.dev·Jul 18 · 3 min readEDR Bypass in 2026: How Attackers Evade Modern Endpoint DetectionTL;DR: EDR tools are more powerful than ever — but so are bypass techniques. Here's what defenders need to know to stay ahead. Why EDR Alone Is Not Enough Endpoint Detection and Response (EDR) platfo00
RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·Jul 16 · 5 min readDetecting Kerberoasting attacks with SplunkNote: The dataset used is fictional Scenario Company IP address: 192.168.1.0/24 What is Kerberoasting? Kerberoasting is an attack that exploits Kerberos Service Tickets to obtain the password hash o00
JSjagmohan singhinjagsingh-security.hashnode.dev·Jul 14 · 7 min readWho Scans the Scanners? Notes on Vulnerability Management Done RightAt one point in my career I took ownership of an enterprise vulnerability management programme that was barely functioning. The scanning platform had been neglected over time, and getting it back to h00
LVLong Voinlongvh0904.hashnode.dev·Jul 13 · 22 min readInvestigation Diary: HTB — BrutusIntroduction "Logs never lie. They just sit quietly, waiting for someone who knows the right question to ask." Brutus is a Very Easy Sherlock on HackTheBox, built around two artifacts every Linux in00
JJJeji Jamesinjeji-james.hashnode.dev·Jul 10 · 2 min readLinux Log Fortress — Access Control & Threat Pattern DetectionIn a real SOC environment, a log file is forensic evidence. Before you can analyze it, you need to protect it. This lab walks through the full workflow from locking down file permissions to hunting fo00
RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·Jul 8 · 3 min readDetecting brute force attacks with SplunkNote: The dataset used is fictional Introduction When a malicious actor wants to log in to a user account, usually they use a password dictionary, and try to log in with each password. In this article00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jul 8 · 9 min readSplunk vs Microsoft Sentinel vs IBM QRadar: Which SIEM Should You Learn First?In today’s hyper-connected digital landscape, organizations generate enormous volumes of security data every second from firewalls and endpoints to cloud workloads and applications. Security Informati00