YPYogeshwar Peelainexploitnotes.hashnode.dev·1d ago · 9 min readTryHackMe : After Hours WriteupSummary The provided archive contains a raw dump of a Windows CIM repository - the backing store for WMI (INDEX.BTR, MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP, OBJECTS.DATA, normally found at C:\Window00
SSaguninsagunwrites.hashnode.dev·4d ago · 6 min readYARA Rules ExplainedIn cybersecurity, finding malware is often like searching for a needle in a huge digital haystack. Organizations may have thousands or even millions of files across their systems. Security researchers00
YPYogeshwar Peelainexploitnotes.hashnode.dev·5d ago · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10
RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·Jul 16 · 5 min readDetecting Kerberoasting attacks with SplunkNote: The dataset used is fictional Scenario Company IP address: 192.168.1.0/24 What is Kerberoasting? Kerberoasting is an attack that exploits Kerberos Service Tickets to obtain the password hash o00
JJJeji Jamesinjeji-james.hashnode.dev·Jul 10 · 2 min readLinux Log Fortress — Access Control & Threat Pattern DetectionIn a real SOC environment, a log file is forensic evidence. Before you can analyze it, you need to protect it. This lab walks through the full workflow from locking down file permissions to hunting fo00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 10 · 7 min readStart Your SOC Journey with SOC Analyst Training 101In today’s digital landscape, cyber threats are evolving at an unprecedented pace. From ransomware attacks targeting critical infrastructure to sophisticated phishing campaigns and advanced persistent00
JJJaewook Junginwoogi.me·Jun 6 · 8 min readThreat Hunting MethodologyMost security tools are reactive. Alerts fire after a rule matches, and analysts triage. Threat hunting flips that: you assume something has already evaded the tools, and you go look for it. This post00
RBRegő Botond Ronyeczinzerohook.hashnode.dev·Jun 4 · 9 min readTop 10 DNS Security Tools for Proactive Threat Hunting (2026)Most DNS security advice is reactive. Something breaks, you investigate. But the teams that catch problems early aren't waiting for alerts from their SIEM — they're actively mapping their own attack s00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 3 · 5 min readWhat Are the Tools Used in a SOC Analyst Workflow?In the fast-paced world of cybersecurity, a SOC Analyst is often the first line of defense against cyber threats. They monitor systems 24/7, investigate alerts, and respond to incidents before they ca00
Vvaishvikkansarainloghunter.hashnode.dev·May 22 · 9 min readHow to Investigate a Phishing Attack Step by Step (SOC Perspective) Phishing is the number one attack vector used by cybercriminals worldwide. According to multiple threat intelligence reports, over 90% of data breaches begin with a phishing email. As a SOC Analyst, k00