JJebitokinsharonjebitok.com·2d ago · 6 min readCTI for Alert Triage (TryHackMe)Link to the challenge on TryHackMe: CTI for Alert Triage Introduction CTI for Alert Triage shifts gears from SIEM pivoting to something a lot of security writeups skip past: how a single high-severity00
JJebitokinsharonjebitok.com·2d ago · 2 min readResponse and Recovery (TryHackMe)Link to the challenge on TryHackMe: Response and Recovery Introduction Response and Recovery picks up where Detection and Analysis left off: the investigation into the compromised l.chen@nexusfinancia00
JJebitokinsharonjebitok.com·3d ago · 2 min readDetection and Analysis (TryHackMe)Link to the challenge on TryHackMe: Detection and Analysis Introduction Detection and Analysis on TryHackMe puts you in the seat of an incident responder investigating a suspected business email compr00
JJebitokinsharonjebitok.com·4d ago · 7 min readTrusted By Default (TryHackMe)Link to the challenge on TryHackMe: Trusted By Default Introduction Trusted By Default is a Splunk-based investigation room on TryHackMe that drops you into a live-fire correlation exercise across web00
ZTZero Trust Threadsinzerotrustthreads.hashnode.dev·4d ago · 5 min readWhat Are Logs, and Why Do Security Teams Care About Them?Something happened on a computer. How would you know? Maybe someone logged in. Maybe an application crashed. Maybe a user accessed a file. Maybe a firewall blocked traffic. Maybe a web server received00
ZTZero Trust Threadsinzerotrustthreads.hashnode.dev·Aug 30 · 6 min readLogs Are Just Systems Telling You What HappenedOpen a log file for the first time and you might see something like: Aug 30 09:14:07 server sshd[4281]: Failed password for user... Aug 30 09:14:11 server sshd[4281]: Failed password for user... Aug 300
4F404 Foundersin404-founders.com·Aug 26 · 7 min readThe Private APN That Became a Route Into OTThe controller was not exposed to the public Internet A controller at a Polish combined heat and power plant was not exposed to the public Internet. The attacker reached it anyway, from a different en00
SSSandra Sydneyinsandrasydney.hashnode.dev·Aug 24 · 3 min readTier-1 SOC Playbook: Detecting and Containing DDoS & Mass Assignment Attacks using NIST SP 800-61Detecting and Containing DDoS & Mass Assignment Attacks using NIST SP 800-61 This standard operating playbook defines the containment protocol for neutralizing high-impact REST API security incidents 00
PSPrateek Srivastavainprateeksrivastav598.hashnode.dev·Aug 23 · 8 min readA Windows Service is Down. Now What?It doesn't matter if it's SQL Server, IIS, a background agent, or a custom app — when a Windows service goes down, the investigation is always the same five moves. Learn the pattern once, apply it to 11R
4F404 Foundersin404-founders.com·Aug 23 · 4 min readZimbra CVE-2026-73570: The SNMP Trap That Became a ShellAn actively exploited command-injection flaw turns a monitoring notification into unauthenticated command execution as the zimbra user. The dangerous part is a feature administrators may barely remem00