This time we have a quick little task to deal with in the form of someone possibly trying to access the passwd file on a webhost with a local file inclusion attack technique. So let’s start our pla...
In this event we’re tasked with investigating an alert relating to the rule SOC147 - SSH Scan Activity stemming from hostname PentestMachine using the IP address of 172.16.20.5. SIEM has caught a f...
In this alert we’re tasked with investigating suspicious usage of the Certutil executable on the “EricProd” host. Event type is marked as LOLBin (Living-off-the-land binary), a Microsoft-signed leg...
This is just a sample post for myself to know that it’s alive and working as intended.
A new version of content is available.