TATameem Amjadinlabsx.hashnode.dev·Jun 15 · 10 min readKG DistributionI Solved 13Cubed's KG Distribution Memory Forensics Lab - Here's the Full Walkthrough Hunting a Sliver C2 implant through a VMware memory dump with MemProcFS, one artifact at a time. The two memory 00
VNVũ Nhật Lâminblog.fiscybersec.com·Jun 9 · 15 min readRemotePE — The Lazarus RAT that lives in memorySummary A subgroup of Lazarus — the North Korea-linked APT known for cryptocurrency heists worth hundreds of millions of dollars — has retired its older tooling (ThemeForestRAT, PondRAT) in favour of 00
VNVũ Nhật Lâminblog.fiscybersec.com·Jun 8 · 13 min readOpen Directory, Open Season: Inside Red Lamassu's JFMBackdoorExecutive Summary A misconfigured open directory did what years of stealth could not: it handed threat hunters the full toolkit of Red Lamassu (also tracked as Calypso and Bronze Medley), a China-nexu00
GGGiovanni Galarzaingiovannigalarza.hashnode.dev·May 28 · 5 min readThe Game PlanThe plan is simple really: learn enough DFIR to land a job in about a year. I also want to be able to make this as affordable as possible. This means the only thing I want to spend on are any certific00
GGGiovanni Galarzaingiovannigalarza.hashnode.dev·May 27 · 3 min readWho am I, why Digital Forensics and everything in betweenOkay, I'll just going to get into it... I'd describe myself as more of a technical support professional, rather than a cybersecurity professional, even though those positions were at cybersecurity com00
JJebitokinsharonjebitok.com·May 8 · 35 min readAI Forensics (TryHackMe)Introduction The world of Digital Forensics is full of pieces needing to be connected, often under a time constraint. This can be a challenging task, but one that many forensics analysts have accompli00
JJebitokinsharonjebitok.com·May 6 · 10 min readHave a Break (TryHackMe)Investigation is a TryHackMe challenge inspired by a real cargo theft incident, set in a fictional ECTA (European Cargo Threat Assessment) framework. The scenario involves a missing refrigerated truck00
CConradWilliamincxnrvd.hashnode.dev·Apr 28 · 39 min readOperation Black Wing: A Qilin Ransomware Affiliate Engagement Against an East African Logistics ProviderIn late 2025 we investigated a ransomware engagement against a financial-logistics company in East Africa, here pseudonymised as NEXUS FREIGHT LTD. The investigation began as a routine "confirm the fa00
Cchatforest_groveinchatforest.hashnode.dev·Mar 25 · 2 min readDigital Forensics & Incident Response MCP Servers — CrowdStrike, TheHive, VirusTotal, Volatility, WazuhAt a glance: DFIR has strong vendor investment — CrowdStrike, Google, TheHive (StrangeBee), and REMnux all ship official MCP servers. Security-Detections-MCP (334 stars) is the standout with autonomous detection engineering. Community fills gaps for ...00
HBHarsh Bhavsarininvestigating-windows-2-cyph34.hashnode.dev·Feb 24 · 11 min readInvestigating Windows 2.0 [TryHackMe]🔗 TryHackMe Challenge room: https://tryhackme.com/room/investigatingwindows2 1. Scenario Overview The Investigating Windows 2.0 challenge simulates a real-world Digital Forensics & Incident Response 00