TLTirthak Likharintirthaklikhar.hashnode.dev·Sep 28 · 6 min readWhat EDR Reveals After a Suspicious Document OpensWhen a Word document launches a command shell and that shell retrieves an executable, there is already a sequence worth investigating. The next question is how far it went. A downloaded file and a run00
Oodufuwababajide77inkay-security-labs.hashnode.dev·Sep 29 · 4 min readNetwork Discovery Detection: Visualizing Scans in Elastic SIEMIf you are training for a SOC analyst role knowing what a network scan won't be enough. You have to know exactly what it looks like in the logs and how to hunt for it. I recently tackled the "Network 00
JJebitokinsharonjebitok.com·Sep 11 · 24 min readThreat Hunting: Introduction Link to the challenge on TryHackMe: Threat Hunting: Introduction Introduction Threat hunting is the systematic, proactive search for malicious activity in your environment that may have evaded detecti00
HCHazel Chirindainhazelsec.hashnode.dev·Sep 11 · 9 min readAI Is Changing Cybersecurity — But It Is Also Changing the AttackerArtificial intelligence is becoming impossible to ignore in cybersecurity. Security vendors are adding AI assistants to their platforms. Analysts can use AI to help summarise incidents, understand ale00
JJebitokinsharonjebitok.com·Sep 9 · 6 min readCTI for Alert Triage (TryHackMe)Link to the challenge on TryHackMe: CTI for Alert Triage Introduction CTI for Alert Triage shifts gears from SIEM pivoting to something a lot of security writeups skip past: how a single high-severity00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readDetection and Analysis (TryHackMe)Link to the challenge on TryHackMe: Detection and Analysis Introduction Detection and Analysis on TryHackMe puts you in the seat of an incident responder investigating a suspected business email compr00
MM1Hinm1h.hashnode.dev·Aug 14 · 13 min readThreat Hunting & Splunk Analysis: Investigating a data leak Objective: My following write up for this challenge is a resource that covers how a SOC analyst operates, it combines my personal investigation along with: Learning Splunk: SPL across Sysmon and Windo10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 8 · 9 min readTryHackMe : After Hours WriteupSummary The provided archive contains a raw dump of a Windows CIM repository - the backing store for WMI (INDEX.BTR, MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP, OBJECTS.DATA, normally found at C:\Window10
SSaguninsagunwrites.hashnode.dev·Aug 5 · 6 min readYARA Rules ExplainedIn cybersecurity, finding malware is often like searching for a needle in a huge digital haystack. Organizations may have thousands or even millions of files across their systems. Security researchers00