JJebitokinsharonjebitok.com·Sep 11 · 24 min readThreat Hunting: Introduction Link to the challenge on TryHackMe: Threat Hunting: Introduction Introduction Threat hunting is the systematic, proactive search for malicious activity in your environment that may have evaded detecti00
HCHazel Chirindainhazelsec.hashnode.dev·Sep 11 · 9 min readAI Is Changing Cybersecurity — But It Is Also Changing the AttackerArtificial intelligence is becoming impossible to ignore in cybersecurity. Security vendors are adding AI assistants to their platforms. Analysts can use AI to help summarise incidents, understand ale00
JJebitokinsharonjebitok.com·Sep 9 · 6 min readCTI for Alert Triage (TryHackMe)Link to the challenge on TryHackMe: CTI for Alert Triage Introduction CTI for Alert Triage shifts gears from SIEM pivoting to something a lot of security writeups skip past: how a single high-severity00
JJebitokinsharonjebitok.com·Sep 9 · 2 min readDetection and Analysis (TryHackMe)Link to the challenge on TryHackMe: Detection and Analysis Introduction Detection and Analysis on TryHackMe puts you in the seat of an incident responder investigating a suspected business email compr00
MM1Hinm1h.hashnode.dev·Aug 14 · 13 min readThreat Hunting & Splunk Analysis: Investigating a data leak Objective: My following write up for this challenge is a resource that covers how a SOC analyst operates, it combines my personal investigation along with: Learning Splunk: SPL across Sysmon and Windo10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 8 · 9 min readTryHackMe : After Hours WriteupSummary The provided archive contains a raw dump of a Windows CIM repository - the backing store for WMI (INDEX.BTR, MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP, OBJECTS.DATA, normally found at C:\Window10
SSaguninsagunwrites.hashnode.dev·Aug 5 · 6 min readYARA Rules ExplainedIn cybersecurity, finding malware is often like searching for a needle in a huge digital haystack. Organizations may have thousands or even millions of files across their systems. Security researchers00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10
RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·Jul 16 · 5 min readDetecting Kerberoasting attacks with SplunkNote: The dataset used is fictional Scenario Company IP address: 192.168.1.0/24 What is Kerberoasting? Kerberoasting is an attack that exploits Kerberos Service Tickets to obtain the password hash o00