YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10
JJebitokinsharonjebitok.com·Jun 12 · 35 min readTraffic Analysis Pitfalls (TryHackMe)Link to the challenge/walkthrough on TryHackMe: Traffic Analysis Pitfalls Introduction It is 02:47. Our SIEM fires an alert. Alert: Large Outbound Transfer Source: 10.10.15.44 (WKST-FINANCE-04) D00