MM1Hinm1h.hashnode.dev·Aug 14 · 13 min readThreat Hunting & Splunk Analysis: Investigating a data leak Objective: My following write up for this challenge is a resource that covers how a SOC analyst operates, it combines my personal investigation along with: Learning Splunk: SPL across Sysmon and Windo10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 8 · 9 min readTryHackMe : After Hours WriteupSummary The provided archive contains a raw dump of a Windows CIM repository - the backing store for WMI (INDEX.BTR, MAPPING1.MAP, MAPPING2.MAP, MAPPING3.MAP, OBJECTS.DATA, normally found at C:\Window10
SSaguninsagunwrites.hashnode.dev·Aug 5 · 6 min readYARA Rules ExplainedIn cybersecurity, finding malware is often like searching for a needle in a huge digital haystack. Organizations may have thousands or even millions of files across their systems. Security researchers00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10
RMRodrigo Martinez Nuñezincyberdefenseprocess.hashnode.dev·Jul 16 · 5 min readDetecting Kerberoasting attacks with SplunkNote: The dataset used is fictional Scenario Company IP address: 192.168.1.0/24 What is Kerberoasting? Kerberoasting is an attack that exploits Kerberos Service Tickets to obtain the password hash o00
JJJeji Jamesinjeji-james.hashnode.dev·Jul 10 · 2 min readLinux Log Fortress — Access Control & Threat Pattern DetectionIn a real SOC environment, a log file is forensic evidence. Before you can analyze it, you need to protect it. This lab walks through the full workflow from locking down file permissions to hunting fo00
TSTech Skill Schoolintechskillschool.hashnode.dev·Jun 10 · 7 min readStart Your SOC Journey with SOC Analyst Training 101In today’s digital landscape, cyber threats are evolving at an unprecedented pace. From ransomware attacks targeting critical infrastructure to sophisticated phishing campaigns and advanced persistent00
JJJaewook Junginwoogi.me·Jun 6 · 8 min readThreat Hunting MethodologyMost security tools are reactive. Alerts fire after a rule matches, and analysts triage. Threat hunting flips that: you assume something has already evaded the tools, and you go look for it. This post00
RBRegő Botond Ronyeczinzerohook.hashnode.dev·Jun 4 · 9 min readTop 10 DNS Security Tools for Proactive Threat Hunting (2026)Most DNS security advice is reactive. Something breaks, you investigate. But the teams that catch problems early aren't waiting for alerts from their SIEM — they're actively mapping their own attack s00