Blog Posts

Categories

Windows Registry Forensics

October 22, 2025Digital Forensic

A walkthrough of Windows registry forensic analysis from evidence acquisition to detailed artifact examination, following proper forensic procedures.

Windows Registry ForensicsRead more →

Network Packet Analysis

October 10, 2025Traffic Analysis

Packet-capture analysis of staged incident data (HTTP, RDP, SSH): identification of file transfer, remote access, and exfiltration indicators.

Network Packet AnalysisRead more →

Analyzing a Web Server Compromise: From Brute Force to Data Exfiltration

August 1, 2025Incident Response

In this blog, we walk through the process of analyzing web server logs after a compromise. Using log analysis, we uncover the attacker's brute force method, successful login, access to sensitive files, and exfiltration techniques. This post provides a detailed approach to understanding and responding to a server breach.

Analyzing a Web Server Compromise: From Brute Force to Data ExfiltrationRead more →

Volt Typhoon APT Intrusion Investigation Report

July 30, 2025Incident Response

Comprehensive forensic investigation into a suspected Volt Typhoon intrusion. Covers initial access via Zoho ManageEngine ADSelfService Plus, execution using WMIC, credential dumping, lateral movement, and log tampering tactics.

Volt Typhoon APT Intrusion Investigation ReportRead more →

Forensic Analysis of an Abandoned Hacker's Laptop

April 11, 2025Digital Forensic

In this forensic walkthrough, we dive into a real-world scenario involving an abandoned Dell CPi notebook suspected of being used for wireless hacking activities. Using a multi-part disk image, we uncover traces of hacking tools, analyze usage artifacts, and attempt to link the digital evidence to the alleged hacker known as 'Mr. Evil.' Join me as we explore how digital forensics helps trace the footsteps of a cyber intruder and piece together their digital trail

Forensic Analysis of an Abandoned Hacker's LaptopRead more →

Digital Forensics Case

February 8, 2025Digital Forensic

Acquire the critical skills of evidence preservation, disk imaging, and artefact analysis for use in court.

Digital Forensics CaseRead more →

Forensic

February 8, 2025Digital Forensic

This memory dump originates from a compromised system. Perform in-depth forensics to explore its internals.

ForensicRead more →

SecureCorp Incident Response Case Study

February 1, 2025

This case study presents a simulated attack against a vulnerable Ubuntu-based environment and concludes with a comprehensive incident response investigation using Redline and other forensic tools.

SecureCorp Incident Response Case StudyRead more →

Hunt ransomware

February 1, 2025Incident Response

An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server.

Hunt ransomwareRead more →

Detecting FTP Brute-Force Attacks Using Wireshark

February 1, 2025Traffic Analysis

In this walkthrough, we’ll use Wireshark to analyze a packet capture and detect a brute-force attack on an FTP server. You’ll learn how to filter FTP traffic, identify repeated login attempts, and trace the attacker's IP address.

Detecting FTP Brute-Force Attacks Using WiresharkRead more →

REvil Corp

February 1, 2025Incident Response

You are involved in an incident response engagement and need to analyze an infected host using Redline

REvil CorpRead more →

Setup Wazuh Lab

January 28, 2025Tooling

Analyze Windows Security Event logs to investigate an attempted RDP brute-force attack.

Setup Wazuh LabRead more →

Traffic Analysis

January 16, 2025Wireshark

This guide demonstrates how to analyze malware traffic using Wireshark,focusing on identifying exploitation attempts and understanding TCP traffic patterns

Traffic AnalysisRead more →

Carnage

January 16, 2024Traffic Analysis

Apply your analytical skills to analyze the malicious network traffic using Wireshark

CarnageRead more →