Rrathsarainrr-cyber.hashnode.dev·Sep 21 · 17 min readNetwork Data Hiding: Covert Channels and Traffic ManipulationConsider a packet capture from a corporate network segment: 23 DNS queries in 21 seconds. Nothing about that number is alarming; DNS is background noise on any live network. Two of those queries are w00
Rrathsarainrr-cyber.hashnode.dev·Sep 18 · 15 min readWindows: Where Data Hides and How It's FoundA file called Secret.exe reports 25 bytes on disk. Nothing in Explorer, nothing in a standard dir listing, and nothing in Task Manager disagrees with that number. Run dir /r instead of dir, and the sa00
Rrathsarainrr-cyber.hashnode.dev·Sep 18 · 13 min readGNU/Linux: Where Data Hides and How It's FoundA filesystem can tell an investigator that everything is consistent while still leaving data outside the paths that ordinary tools inspect. Hidden filenames are the easy case. More interesting cases i00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readPost-Incident Activity (TryHackMe)Link to the challenge on TryHackMe: Post-Incident Activity Introduction Post-Incident Activity closes out the Nexus Financial BEC investigation series, shifting from "what happened during the incident00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readResponse and Recovery (TryHackMe)Link to the challenge on TryHackMe: Response and Recovery Introduction Response and Recovery picks up where Detection and Analysis left off: the investigation into the compromised l.chen@nexusfinancia00
Rrathsarainrr-cyber.hashnode.dev·Sep 3 · 11 min readWindows Memory Forensics: Finding a Live Infection with VolatilityPID 1484 had been running since boot. Nothing about that was unusual: it was Explorer.exe, the process every Windows machine on earth is running right now. What was unusual was the process hanging off00
Rrathsarainrr-cyber.hashnode.dev·Sep 3 · 9 min readGNU/Linux Memory Forensics: Is the Compromise Still Live?It's easy to think of memory forensics purely as a hunt for something malicious. On this case, a GNU/Linux server that had already been through a full attack chain, initial access, privilege escalatio00
MMageshin0xog.hashnode.dev·Aug 24 · 6 min readAPIWizards Breach-Tryhackme WalkthroughLink to the room https://tryhackme.com/room/apiwizardsbreach Task 1:Preparation You were hired as a dedicated external DFIR specialist to help the APIWizards Inc. company with a security incident in t00
Rrathsarainrr-cyber.hashnode.dev·Aug 15 · 10 min readWhat We Got: From Cloud Security Platform to Operational CapabilityA few months after the operationalizing work covered in the last article, it stopped being a project. It became part of how we worked. This article is about what changed once that happened. The Metri00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10