TryHackMe
18 write-ups · most recent first
PS Eclipse — Splunk Log Analysis
MEDIUMSIEM / Log AnalysissplunkSysmonWindows Event Logs
Read on Medium
Carnage Network Traffic Analysis
MEDIUMNetwork AnalysisInvestigating a PCAP file
wiresharknetwork analysis
Read on Medium
ItsyBitsy Web App Log Analysis from Elastic
MEDIUMSIEM / Log Analysiselasticelk
Read on Medium
Benign Windows Log Analysis from Splunk
MEDIUMSIEM / Log Analysissplunkrce
Read on Medium
Tempest Application, Endpoint, Network Analysis Lab
EASYEndpoint Analysistemptestendpoint analysiswindows
Read on Medium
Boogeyman 1 — Email, Endpoint, Network Packet Analysis
MEDIUMNetwork Analysisemailemlnetwork analysis
Read on Medium
Boogeyman 3 — Analysis With Splunk
MEDIUMSIEM / Log Analysiselkelasticlog analysis
Read on Medium
Investigating with Splunk
MEDIUMSIEM / Log Analysisexploitationpersistenceprivilege escalation
Read on Medium
Friday Overtime
MEDIUMThreat IntelIOCVirusTotalMalware Analysis
Read on Medium
Monday Monitor
EASYSIEM / Log AnalysiselkelasticSysmon Log Analysis
Read on Medium
SeeTwo - Network & Binary File Analysis
MEDIUMNetwork Analysiswiresharkpyinstxtractorbinary file analysis
Read on Medium
Slingshot
MEDIUMSIEM / Log Analysissplunksplunk visualizeapache logs
Read on Medium
SigHunt — SIGMA Rule Creation with IOCs
MEDIUMSIGMA RuleSIGMARule CreationSIEM Rule
Read on Medium
Hunt Me I: Payment Collectors
MEDIUMSIEM / Log Analysiswinlogbeatwindows event logssysmon log
Read on Medium
Hunt Me II: Typo Squatters
MEDIUMSIEM / Log Analysiswinlogbeatsysmon logexploitationpersistenceprivilege escalation
Read on Medium
Tardigrage — Incident Response Room
MEDIUMEndpoint Analysissystem logslinux logsexploitationpersistenceprivilege escalation
Read on Medium
MalBuster — Static Analysis
HARDMalware AnalysisGHidraPEStudioVirusTotalPE-BearCAPA
Read on Medium
Masquerade
MEDIUMNetwork Analysiswiresharkwindows event viewerDecryption with python script
Read on Medium