Scenario Mike is a young entrepreneur that recently started a pharmaceutical company online that supplies personal health products. As the business is growing at a rapid pace, Mike pressured the d...
This is a write-up for the LetsDefend Challende - REvil Ransomware, where we’re tasked with investigating a memory dump of a compromised machine to find evidence of the ransomware attack the system...
In this exercise we’re notified of suspicious Rundll32 activity and told to check it out. Define Threat Indicator First of all we need to check if the alert actually checks out, and doing a quick...
Mr Robot likely needs no introductions, and in this room we’re going to tackle a CTF built around the theme of this hit TV series. This is rated suitable for beginners, and it doesn’t require too m...
In this exercise we’re notified of multiple suspicious FTP connection attempts, so let’s dive into the logs and try to figure out what’s what. Detection Data Collection First things first we nee...
Scenario The SOC received an alert in their SIEM for ‘Local to Local Port Scanning’ where an internal private IP began scanning another internal system. Can you investigate and determine if this a...
This time we have a quick alert (oops, did I already give away the final answer?) to check out, so without any further ado, let’s get defending. Understand Why the Alert Was Triggered The SIEM a...
Overpass 2 - Hacked is a great blue team room on TryHackMe, and in this write-up we’re going to dig into clearing it and answering all the questions the room throws at us. Forensics - Analyse the ...
In SOC143 we’re informed of a potential password stealing file having been detected in the email system, so let’s get to the bottom of this. Alert The SIEM alert we receive includes all the relev...
The following write-up covers the SOC146 - Phishing Mail Detected - Excel 4.0 Macros task on LetsDefend. Alert We receive an alter that a phishing attack has been detected, and that iit carries a...
A new version of content is available.