Home
Eero Nevaluoto
Cancel

BTLO - Defaced - Write-Up

Scenario Mike is a young entrepreneur that recently started a pharmaceutical company online that supplies personal health products. As the business is growing at a rapid pace, Mike pressured the d...

LetsDefend - Challenge - REvil Ransomware - Write-Up

This is a write-up for the LetsDefend Challende - REvil Ransomware, where we’re tasked with investigating a memory dump of a compromised machine to find evidence of the ransomware attack the system...

LetsDefend - SOC125 - Suspicious Rundll32 Activity - Write-Up

In this exercise we’re notified of suspicious Rundll32 activity and told to check it out. Define Threat Indicator First of all we need to check if the alert actually checks out, and doing a quick...

TryHackMe - Mr Robot CTF - Write-Up

Mr Robot likely needs no introductions, and in this room we’re going to tackle a CTF built around the theme of this hit TV series. This is rated suitable for beginners, and it doesn’t require too m...

LetsDefend - SOC135 - Multiple FTP Connection Attempt - Write-Up

In this exercise we’re notified of multiple suspicious FTP connection attempts, so let’s dive into the logs and try to figure out what’s what. Detection Data Collection First things first we nee...

BTLO - Network Analysis – Web Shell - Write-Up

Scenario The SOC received an alert in their SIEM for ‘Local to Local Port Scanning’ where an internal private IP began scanning another internal system. Can you investigate and determine if this a...

LetsDefend - SOC167 - LS Command Detected in Requested URL - Write-Up

This time we have a quick alert (oops, did I already give away the final answer?) to check out, so without any further ado, let’s get defending. Understand Why the Alert Was Triggered The SIEM a...

TryHackMe - Overpass 2 - Hacked - Write-Up

Overpass 2 - Hacked is a great blue team room on TryHackMe, and in this write-up we’re going to dig into clearing it and answering all the questions the room throws at us. Forensics - Analyse the ...

LetsDefend - SOC143 - Password Stealer Detected - Write-Up

In SOC143 we’re informed of a potential password stealing file having been detected in the email system, so let’s get to the bottom of this. Alert The SIEM alert we receive includes all the relev...

LetsDefend - SOC146 - Phishing Mail Detected - Excel 4.0 Macros - Write-Up

The following write-up covers the SOC146 - Phishing Mail Detected - Excel 4.0 Macros task on LetsDefend. Alert We receive an alter that a phishing attack has been detected, and that iit carries a...