MCmhk cyberinmhk-cyber.hashnode.dev·8h ago · 6 min readMy First Wireshark PCAP: Kongtuke Rebuke! So I decided to learn Wireshark. I watched like a 20minute video on YouTube, understood the basics, how to apply filters, conversations, endpoints, some of the protocols, etc. Nothing too crazy. Then 00
JJebitokinsharonjebitok.com·Sep 22 · 10 min readPacked Light: Wireshark x Cryptography - XOR & Base64 - Forensics (TryHackMe)Link to the challenge on TryHackMe: Packed Light 🛎️ Concierge Briefing Tiny packets. Odd hours. Suspiciously regular. Someone's smuggling out the data equivalent of a hotel towel every night, folded00
RHRobin Hayerinrobinhayer.hashnode.dev·Sep 21 · 5 min readThe tool said it wrote 48 packets. Only 44 were thereRecap I have been developing a tool wrapped around tshark. The first blog post was about hitting a wall on a 2.5 GB file. Later, I talked about parallelizing the PCAP processing in my second blog post00
PPreetimantinpreetimant.hashnode.dev·Sep 15 · 14 min readUnderstanding Modbus/TCP Through Packet Analysis — HTB Watch TowerWhile working through Hack The Box's ICS/SCADA track, I completed Watch Tower, an introductory packet-analysis lab built around Modbus/TCP traffic. The challenge itself was fairly short: a PCAP captur00
RHRobin Hayerinrobinhayer.hashnode.dev·Aug 26 · 5 min readConcurrency Without a Parallel Parser: Splitting PCAPs by SessionWhere the last post left off In my first post about the 2.5 GB wall, streaming fixed memory. It didn't fix throughput. The pipeline was still one file, one tshark process, one core. Piping stdout to s00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 35 min readTryHackMe : Overflow The Jackpot writeup# Challenge Category Flag 1 B1t Recovery Crypto THM{[REDACTED]} 2 Lost Fortune Included Web THM{REDACTED} 3 Casino Heist Forensics THM{REDACTED} 4 Fresh Powder - Bonus Challenge Detection Eng10
RHRobin Hayerinrobinhayer.hashnode.dev·Aug 10 · 4 min readThe 2.5 GB Wall: Why My tshark Wrapper Died, and How Streaming Fixed ItThe tool that worked I built a CLI tool that wrapped tshark for PCAP analysis. Grab the file, send shell commands, let tshark analyze it, capture the output, shape it, return it. Quite simple, right. 00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 10 · 15 min readTryHackMe : WhyHackMe writeupSummary WhyHackMe is an medium Linux box that chains a handful of low-friction bugs into root. Anonymous FTP leaks a hint pointing at a pass.txt file that's only reachable from localhost. The blog app10
KMkareem Mohamedinkmb.hashnode.dev·Aug 10 · 4 min readPacked Light: A walkthrough of THM Hacker Holidays - Day 4Here is a quick walkthrough of a room for TryHackMe Hacker Holidays 2026, a 14-day cybersecurity challenge where a new room unlocks every day, which started on July 27th.Link: https://tryhackme.com/ro00
YPYogeshwar Peelainexploitnotes.hashnode.dev·Aug 4 · 6 min readTryHackMe : Packed Light WriteupTL;DR A .pcapng capture shows a victim host on 192.168.1.141 downloading a Python keylogger (updates.py) from an attacker-controlled "hotel update server" at byte-lotus-hotel.thm:8080 (34.41.103.191).10