RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·3d ago · 5 min readDetecting Kerberoasting attacks with SplunkNote: The dataset used is fictional Scenario Company IP address: 192.168.1.0/24 What is Kerberoasting? Kerberoasting is an attack that exploits Kerberos Service Tickets to obtain the password hash o00
JJJeji Jamesinjeji-james.hashnode.dev·Jul 10 · 2 min readLinux Log Fortress — Access Control & Threat Pattern DetectionIn a real SOC environment, a log file is forensic evidence. Before you can analyze it, you need to protect it. This lab walks through the full workflow from locking down file permissions to hunting fo00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 10 · 7 min readStart Your SOC Journey with SOC Analyst Training 101In today’s digital landscape, cyber threats are evolving at an unprecedented pace. From ransomware attacks targeting critical infrastructure to sophisticated phishing campaigns and advanced persistent00
JJJaewook Junginwoogi.me·Jun 6 · 8 min readThreat Hunting MethodologyMost security tools are reactive. Alerts fire after a rule matches, and analysts triage. Threat hunting flips that: you assume something has already evaded the tools, and you go look for it. This post00
RBRegő Botond Ronyeczinzerohook.hashnode.dev·Jun 4 · 9 min readTop 10 DNS Security Tools for Proactive Threat Hunting (2026)Most DNS security advice is reactive. Something breaks, you investigate. But the teams that catch problems early aren't waiting for alerts from their SIEM — they're actively mapping their own attack s00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 3 · 5 min readWhat Are the Tools Used in a SOC Analyst Workflow?In the fast-paced world of cybersecurity, a SOC Analyst is often the first line of defense against cyber threats. They monitor systems 24/7, investigate alerts, and respond to incidents before they ca00
Vvaishvikkansarainloghunter.hashnode.dev·May 22 · 9 min readHow to Investigate a Phishing Attack Step by Step (SOC Perspective) Phishing is the number one attack vector used by cybercriminals worldwide. According to multiple threat intelligence reports, over 90% of data breaches begin with a phishing email. As a SOC Analyst, k00
ZOZeroTrust Opsinnavyacyber.hashnode.dev·Apr 30 · 10 min readMy First Hands-On Threat Hunting Workshop Experience with Intel 471: Hunting CVE-2023-46604 from Curiosity to ConfidenceWhen I first heard about Intel 471’s Intelligence-Driven Threat Hunting Workshop: Vulnerability Post-Exploitation Behaviors, I wasn’t actively searching for another certification or workshop. In fact,00
TATaji Abdullahintechnofiles.hashnode.dev·Apr 23 · 2 min readUnderstanding Threat Hunting InitiationWhen I first learned about Threat Hunting, the biggest question I had was, how is the hypothesis formed, how do you come to the point of forming a hypothesis that serves as the basis for the threat hu00
PPromiseinpromise-security.hashnode.dev·Apr 5 · 2 min readAnalysing a Simulated Web Breach with Splunk (Deloitte Forage Cyber Task)1. Getting the logs into Splunk The task provided a web_activity.log file with HTTP requests grouped by internal IP addresses. My first step was to bring this data into Splunk so I could query and vis00