Rroutetorootinblog.routetoroot.io·4d ago · 4 min readLab 24: The Attack Ran. The Alerts Fired.In Lab 13, I ran a brute force attack and got zero alerts. In Lab 24, I ran the same attack in Splunk. 15 alerts fired in under 2 seconds. That's the difference between a detection gap and a detection10
JJebitokinsharonjebitok.com·Sep 23 · 7 min readZero Tolerance (TryHackMe)Link to the challenge on TryHackMe: Zero Tolerance It was supposed to be a regular morning at ProbablyFine Ltd. L2 had just returned from paternity leave. L3 was hosting a live webinar on "Proactive 03B
JJebitokinsharonjebitok.com·Sep 23 · 16 min readPromotion Night: Splunk (TryHackMe)Link to the challenge on TryHackMe: Promotion Night It was a glorious Friday at ProbablyFine Ltd. After weeks of sales calls and PoC demos, the team finally signed a contract with DeceptiTech - a maj00
Rroutetorootinblog.routetoroot.io·Sep 22 · 4 min readLab 23: Writing My First Splunk Detection RuleLab 22 got Splunk running. 180 events indexed. 76 SSH brute force events confirmed in the index. The pipeline was alive. But a SIEM with no detection rules is still just a search engine. Lab 23 is whe00
JJebitokinsharonjebitok.com·Sep 22 · 2 min readSplunk: Exploring SPL (TryHackMe)Link to the challenge on TryHackMe: Splunk: Exploring SPL index=windowslogs index=windowslogs earliest="04/15/2022:08:05:00" latest="04/15/2022:08:06:00" | stats count index=windowslogs EventI00
Rroutetorootinblog.routetoroot.io·Sep 11 · 4 min readLab 22: Same Logs, New SIEM — Setting Up Splunk From ScratchLab 21 closed the detection gap in Elastic. 31 alerts fired. End-to-end detection confirmed. The Elastic SIEM phase of the portfolio was complete. So naturally, I installed a second SIEM. Lab 22 is th00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readDetection and Analysis (TryHackMe)Link to the challenge on TryHackMe: Detection and Analysis Introduction Detection and Analysis on TryHackMe puts you in the seat of an incident responder investigating a suspected business email compr00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readPost-Incident Activity (TryHackMe)Link to the challenge on TryHackMe: Post-Incident Activity Introduction Post-Incident Activity closes out the Nexus Financial BEC investigation series, shifting from "what happened during the incident00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readResponse and Recovery (TryHackMe)Link to the challenge on TryHackMe: Response and Recovery Introduction Response and Recovery picks up where Detection and Analysis left off: the investigation into the compromised l.chen@nexusfinancia00
JJebitokinsharonjebitok.com·Sep 8 · 5 min readThe Blue Team Perspective (TryHackMe)Link to the Challenge on TryHackMe: The Blue Team Perspective index=botsv1 | stats count by sourcetype index=botsv1 sourcetype=fgt_utm subtype=ips | stats count by srcip | sort -count | head 1 i00