UPLINK SOC / WRITE-UPS TLP:CLEAR OPERATIONAL PORTFOLIO GITHUB LAST.SYNC · 2026-07-23
portfolio/write_ups
indexed 361
platforms 8
last_sync 2026-07-23

Write-Ups Collection

CTF challenges & cybersecurity lab solutions — documented, reproducible, verifiable on source

Total write-ups
361entries
CyberDefenders
81
LetsDefend
75
Centri · Blue Team Labs Online
72
Platforms
8
Platform
Difficulty
CyberDefenders
CyberDefenders → CyberDefenders - CyberRange
CYBERDEFENDERS · 81
Threat Intel
Trace the 3CX supply chain compromise using VirusTotal to identify malicious DLLs, evasion TTPs, malware family, and the responsible APT group
virustotalaptsupply-chainmalwaret1574
Mobile Forensics
Examine an Android image to confirm APT35 spyware disguised as a VPN, recovering its C2 domain, SMS-stealing functions, and permissions
jadxapksqlitespywarec2
Network Forensics
Analyze a VoIP honeypot pcap and log to uncover SIP scanning tools, dialed numbers, credentials, and RTP codec details
wiresharksiprtpvoipsipvicious
Windows DFIR
Examine a suspect's Windows disk image to recover browser searches, FTP servers, deleted files, Tor usage, and cracked login passwords
autopsyftk-imagermimikatzshellbagsrifiuti2
Mobile Forensics
Analyze an Android dump to trace a malicious APK download, decompile it, and recover exfiltration channels, encryption keys, and leaked credentials
aleappjadxapkcyberchefsqlite
Memory Forensics
Investigate a memory image to trace USB-borne Andromeda bot propagation, dropped payloads, C2 infrastructure, and the reactivating APT group
memprocfsvolatilityusbstorvirustotalevtxcmd
Memory Forensics
Analyze a memory image of a banking-malware infection to trace a malicious PDF exploit, embedded JavaScript, shellcode, and C2 connections
volatilitypdf-toolsshellcodemalfindt1203
Memory Forensics
Analyze a memory dump infected with BlackEnergy v2 to identify the suspicious process, code injection, and the injected DLL's base address
volatilitymalfinddll-injectiont1055.001virustotal
Network Forensics
Correlate pcap and event logs to reconstruct a BlueSky ransomware attack from SQL brute force through privilege escalation, persistence, and credential dumping
wiresharknetworkminerransomwarepcapevent-logs
Memory Forensics
Analyze a Windows memory image to enumerate browser processes, network connections, executable hashes, and PowerShell parent activity
volatilitynetscanhxdcertutilt1071.001
Threat Hunting
Hunt across SIEM logs to trace a phishing-driven intrusion through execution, defense evasion, lateral movement, credential dumping, and persistence
splunkelksiemprocess-injectionkerberos
Windows DFIR
Examine a Windows disk image to recover system build, users, file metadata, recycle bin contents, and installed browsers
ftk-imagerregistry-explorerregripperhindsightsqlite
Memory Forensics
Analyze a memory image to uncover a hidden unlinked process, its injected PEs, pool tags, and full path using Volatility and volshell
volatilitypsxviewprocess-injectionvolshellt1055
Memory Forensics
Analyze a memory dump of a Meterpreter infection to extract the infected PID, attacker IP, VBS script, hashes, and VAD protections
volatilitymeterpreternetscanhashdumpvad
Endpoint Forensics
Analyze Chromebook and Google Takeout artifacts to reconstruct downloads, browser activity, and user location history
chromebookgoogle-takeoutsqlitecyberchefcleapp
Malware Analysis
Dissect a malicious RTF exploiting CVE-2017-11882 to extract its obfuscated shellcode, payload URL, and download-and-execute functions
rtfdumpscdbgshellcodecve-2017-11882t1140
Network Forensics
Trace an SSH brute-force intrusion through PCAP and Linux logs to recover credentials and reconstruct malware installation and persistence
pcapwiresharksshbruteforcelinux
Malware Analysis
Reverse a malicious fake ChatGPT browser extension to expose its keylogging, cookie theft, encryption, and C2 exfiltration behavior
browser-extjavascriptbase64c2keylogger
Windows DFIR
Investigate a Fog Ransomware infection from a phishing RAR through PowerShell execution, BYOVD privilege escalation, persistence, and encryption impact
ransomwarekapepowershellevtxeztools
Malware Analysis
Dissect a malicious PDF captured in PCAP to extract obfuscated JS object streams, shellcode, and CVE exploits that drop executables
pdfjavascriptshellcodescdbgwireshark
Malware Analysis
Analyze a malicious LNK dropper that launches mshta-driven HTA/JS payloads, decrypt its stages, and attribute the campaign to an APT group
lnkmshtahtaprocmoncyberchef
Threat Hunting
Hunt a password-spray-to-domain-compromise attack in Splunk, tracing RDP lateral movement, credential dumping, and Kerberos ticket abuse
splunksysmonkerberoslateral-movementpassword-spray
Threat Intel
Analyze a MetaMask phishing kit to recover stolen seed phrases and pivot through its Telegram bot to unmask the phishing actor
phishingosintphptelegrammetamask
Linux DFIR
Examine a compromised Linux web server disk image to determine SSH brute-force access, crack credentials, and identify attacker-created accounts
disk-forensicftk-imagerauth.logjohntheripperssh
Log Analysis
Correlate honeypot auth, kernel, and Apache logs to profile SSH brute-force attackers, firewall changes, and dropped scanning tools
auth.logapache2honeypotsshgrep
Network Forensics
Profile capture endpoints, DNS queries, and hosts in a PCAP to trace malware delivered via a malicious invoice email and its exfiltration
pcapwiresharknetworkminerdnsgeoip
Windows DFIR
Analyze a Windows disk image via registry hives and browser artifacts to answer OS, user, and case-related questions about the suspect
disk-forensicregistryftk-imagerautopsyeztools
Network Forensics
Analyze honeypot PCAP traffic to identify an SMB buffer-overflow exploit, decode its shellcode, and track downloaded malware
pcapwiresharksmbshellcodescdbg
Windows DFIR
Examine a suspect Windows forensic image to confirm illegal port-scanning activity, identifying the scanner tool, timing, and open ports
disk-forensicregistryprefetchftk-imagereztools
Cloud Security
Investigate an AWS SSRF-to-IMDS attack via PCAP and CloudTrail logs to trace IAM credential theft, S3 exfiltration, and bucket deletion
awsssrfcloudtrailimdss3
Threat Intel
Pivot from an IcedID sample hash through VirusTotal and OSINT to map dropped payloads, hosting domains, and the responsible threat actor
icedidvirustotalmalpediaxlsmioc
Memory Forensics
Analyze a memory image of an IcedID-compromised endpoint to trace ISO delivery, malicious execution, persistence, and the payload DLL
volatilitymemprocfsisoicedidevtx
Windows DFIR
Mount a breached web server's disk and memory image to trace SQL injection and LFI exploitation of DVWA and the attacker's rogue user creation
volatilityftk-imagerregrippersql-injectiont1190
Linux DFIR
Examine a Kali Linux disk image to trace an insider's credential-dumping downloads, bash history, and hidden files proving lateral attacks
ftk-imagerbash_historykaliapachet1003
Mobile Forensics
Parse an iPad iOS filesystem with iLEAPP and SQLite to recover device details, browsing history, jailbreak app, and installed applications
ileappiossqlitemac_aptautopsy
AD / Kerberos
Hunt domain controller logs in Splunk to detect RC4 Kerberoasting, identify the compromised service account, RDP logins, and WMI persistence
kerberoastingsplunkevent-4769rc4-hmacsysmon
OSINT
Use OSINT, GitHub leaks, and image geolocation to unmask an insider attacker's identity, leaked credentials, and physical whereabouts
osintsherlockgithubgoogle-mapst1078
Threat Intel
Pivot on a malicious MSIX installer hash in VirusTotal to profile the batloader family, dropped executables, C2 domains, and threat actor
virustotalbatloadermsixmitrec2
Malware Analysis
Statically analyze a macro-laden malicious Office document with oledump and olevba to extract the base64 PowerShell dropper and its IOCs
oledumpolevbamacrobase64wmi
Windows DFIR
Investigate KAPE-collected Windows artifacts to trace a malicious PyPi package install, Defender disabling, C2 traffic, and persistence
ez-toolsprefetchpecmdpowershellc2
Windows DFIR
Analyze KAPE triage artifacts to reconstruct a GPO-delivered wiper attack, its staging, Defender exclusions, and boot manager destruction
wipermftecmdsysmongpousn
Incident Response
Trace an APT29-style .rdp spear-phishing campaign through SIEM logs, covering initial access, DLL beacon, persistence, and privilege escalation
apt29splunkelkrdpphishing
Linux DFIR
Explore a Linux gamer's disk image using bash history and SQLite artifacts to uncover Log4j exploit attempts and user activity anomalies
ftk-imagersqlitebash_historylog4jfirefox
Memory Forensics
Analyze memory dumps with Volatility to identify a phishing-delivered RAT, its process injection, persistence, and stolen credential hashes
volatilityratphishingprocess-injectionntlm
Memory Forensics
Use Volatility to spot a masquerading svchost process injected under explorer, extract its hidden hash, and recover alternate data stream artifacts
volatilityprocess-injectionadst1055.012base64
Network Forensics
Dissect a drive-by exploit-kit PCAP, deobfuscating malicious JavaScript to identify served CVEs, executables, and geo-targeted redirects
pcapwiresharkspidermonkeyjavascriptexploit-kit
Malware Analysis
Deobfuscate a malicious document's macros and dropped JavaScript backdoor using oledump and olevba to reveal its decryption key and staging logic
oledumpolevbajavascriptwscriptt1140
Threat Intel
Analyze a malicious PPT dropper to identify the Stealc family, its C2 server, RC4 key, and credential-theft behavior via VirusTotal and Any.Run
virustotalany.runstealcpptrc4
Network Forensics
Investigate an insider's PCAP to recover FTP creds, DNS lookups, TLS session keys, and image EXIF metadata using Wireshark and NetworkMiner
pcapwiresharkftptlsdns
Email / Phishing
Investigate a phishing email and its malicious URL distributing BitRAT, AsyncRAT, and CoinMiner using threat intel tools to extract IOCs
emlbitratasyncratcoinminerurlhaus
Windows DFIR
Examine a disk image to trace a fake-giveaway phishing compromise through WhatsApp artifacts, a macro-laden doc, and dropped malware
autopsyftk-imageroledumpwhatsappmacros
Malware Analysis
Reverse engineer the Phobos ransomware to uncover its hashing, encryption logic, C2 protocol, and process-termination and persistence functions
idaghidrax64dbgransomwarephobos
Network Forensics
Trace an LLMNR/NBT-NS poisoning attack in a PCAP to identify the rogue machine, compromised account, and SMB host accessed
pcapwiresharkllmnrnbt-nssmb
Malware Analysis
Analyze a Kimsuky APT malicious PDF to trace embedded JavaScript, memory-permission APIs, and a multi-stage PE32 payload downloaded from C2
pdfjavascriptghidrakimsukyshellcode
Network Forensics
Analyze PCAP traffic to reconstruct PsExec lateral movement, identifying the pivot hosts, auth account, service executable, and network shares used
pcapwiresharkpsexecsmbdcerpc
Memory Forensics
Analyze a memory dump with Volatility 3 to identify the QBot-infected Excel process, extract the malware, and uncover its C2 communications
volatility3qbotnetscanpstreedumpfiles
Malware Analysis
Dissect a weaponized WinRAR ZIP exploiting CVE-2023-38831 to decrypt multi-stage payloads, identify injected shellcode, and its download C2
cve-2023-38831winrarcyberchefshellcodescdbg
Reverse Engineering
Work through binary analysis exercises extracting flags from ELF files, obfuscated JavaScript, Brainfuck, and a corrupted encrypted ZIP
ghidraidastringsbase64brainfuck
Memory Forensics
Analyze a memory dump with Volatility to trace the Ramnit malware process, its executable path, C2 IP, and compilation timestamp
volatilitymemorynetscanfilescanramnit
Threat Intel
Investigate a RedLine Stealer sample by hash using VirusTotal and ThreatFox to map its MITRE techniques, C2 IPs, YARA rule, and DLLs
virustotalredlinemalwarebazaarthreatfoxyara
Memory Forensics
Analyze a memory dump with Volatility and Redline to identify the oneetx.exe process, its injection, VPN connection, and malware family
volatilitymalfindredlinet1055pstree
Memory Forensics
Analyze a Windows memory dump with Volatility 3 to trace a PowerShell-launched stealer, its second-stage payload, remote share, and family
volatility3pstreecmdlinerundll32stealer
Memory Forensics
Investigate a Linux CentOS memory dump with Volatility to uncover a reverse shell, persistence backdoor, and the attacker's rootkit and key
volatilitylinuxrootkitcentoscyberchef
Windows DFIR
Hunt an Active Directory intrusion in Splunk, tracing reverse-shell initial access, run-key persistence, AS-REP roasting, rogue DC creation, and data staging
splunksysmonas-rep-roastactive-directorypersistence
Mobile Forensics
Examine a macOS Catalina disk image with mac_apt to recover Safari bookmarks, Notes, iMessage permissions, quarantine records, and steganographic secrets
mac_aptmacosautopsysqlitesteghide
Windows DFIR
Investigate a compromised bank workstation to trace a WinRAR CVE-2023-38831 exploit, second-stage payload, event-log tampering, persistence, and data staging
winrarcve-2023-38831mftecmdprefetchjumplist
Windows DFIR
Analyze a disk image of a fake SysInternals download using AmCache and registry artifacts to identify the malware, its C2 domain, dropped payload, and service
amcacheftk-imagervirustotalappcompatcachet1071
Incident Response
Correlate disk images, memory dumps, and a pcap to reconstruct an RDP-borne intrusion, identify the malicious process migration, C2 IPs, and attack toolkit
volatilitypcape01registrymemory-forensics
Threat Hunting
Hunt BITS-job persistence in Splunk using Security and Defender logs to identify the backdoor framework, scheduled task, LOLBAS, and attacker IP
bitsadmint1197splunkdefenderschtasks
Memory Forensics
Analyze memory dumps with Volatility to uncover a TeamViewer-abusing RAT delivered via a malicious Office document, tracing C2, remote-access ID, and phishing
volatilitymalfindteamviewerofficemalscannernetscan
Mobile Forensics
Parse an Android image with ALEAPP to reconstruct a murder victim's trading app, debts, SMS, location history, and Discord meeting arrangements
androidaleappsqlitebrowsersmsdiscord
Network Forensics
Analyze a pcap to trace a Tomcat compromise from port scanning and Gobuster enumeration through admin-panel brute force, reverse-shell upload, and persistence
wiresharkpcaptomcatgobusternetworkminer
Incident Response
Investigate a Trigona ransomware attack across file server and IT machine to trace RDP initial access, enumeration, exfiltration, lateral movement, and encryption
trigonaransomwareevtxecmdkaperdp
Linux DFIR
Investigate a compromised Linux server with Volatility and disk analysis to trace SSH brute force, an exploited service, downloaded files, and data exfiltration
volatilityauth.loglinuxmemory-forensicsautopsy
Reverse Engineering
Reverse the packed ShadowSteal stealer in IDA and Ghidra to recover its mutex string, RC4 key, version, screenshot routine, and self-delete command
idaghidrax64dbgstealerrc4
Network Forensics
Analyze web-server traffic to trace a SQL injection attack, identify the vulnerable script, dumped databases, discovered directory, credentials, and uploaded shell
pcapwiresharksqlinetworkminerwebshell
Network Forensics
Examine a pcap to trace a PHP web-shell upload, identify the attacker's origin and user agent, the upload directory, shell port, and exfiltrated file
wiresharkpcapwebshellexfiltrationphp
Network Forensics
Dissect multiple packet captures to analyze DHCP, DNS, SMB, and reverse-shell traffic, extracting flags, transaction IDs, file paths, and netcat details
wiresharkpcapsmbdhcpdns
Malware Analysis
Analyze two Excel 4.0 macro documents on REMnux to crack encryption, reveal hidden sheets, decode anti-analysis checks, and extract payload URLs and families
xlm-macrosoledumpxlmdeobfuscatorremnuxolevba
Threat Intel
Pivot a malware hash through VirusTotal to identify the Yellow Cockatoo RAT family, its dropped files, compile timestamp, and C2 server
virustotalmalwarepe-headerc2infostealer
Network Forensics
Correlate PCAP and IDS alerts with NetworkMiner and Wireshark to map a Zeus bot infection, its C2 server, and WordPress compromise
pcapwiresharknetworkminerzeusvolatility
Centri · Blue Team Labs Online
Security Blue Team → Blue Team Labs Online → BTLO - Investigations
BTLO · 72
Malware Analysis
Analyze two OneNote malware samples with OneNoteAnalyzer and CyberChef to extract embedded HTA scripts and download URLs for an IOC report
onenoteonenoteanalyzercyberchefhtat1587.001
Windows DFIR
Mount a VHDX and build a timeline with MFTECmd and Registry Explorer to reconstruct a break-in involving anti-forensic tooling and data theft
kapemftecmdregistry-explorertimelineaf015
Windows DFIR
Parse BITS jobs with BitsParser to uncover attacker persistence and file downloads such as winPEAS on a compromised Windows host
bitsparsert1197winpeaspersistencejson
Memory Forensics
Run a Volatility 2 investigation on a Cridex-infected memory dump to find the malicious process, C2 connection, and targeted banking domains
volatilitycridexpslistbanking-trojant1566.002
Reverse Engineering
Perform static PE analysis of the Basilisk malware with CFFExplorer, PEiD, and BinText to enumerate imports, entry point, packing, and build time
cffexplorerpeidbintextexeinfope-analysis
Malware Analysis
Analyze a malicious Excel document to extract VBA-macro shellcode and parse the embedded Cobalt Strike beacon configuration and IOCs
oledumpcyberchefcobalt-strikevba-macroxlsm
Malware Analysis
Investigate a phishing email and its dropped keylogger malware, tracing mutex, persistence locations, and C2 communication
noribenemlftk-imagert1566.002t1056.001
Security Operations
Explore Sysmon 14 FileBlockExecutable events to identify blocked malware downloads and craft configs to prevent executable drops
sysmonevent-viewereventid-27urlhausosint
Network Forensics
Analyze packet captures to detect exploitation of Openfire CVE-2023-32315, tracking admin account creation, plugin upload, and reverse shell
wiresharkopenfirecve-2023-32315t1190webshell
Incident Response
Investigate web server logs and a MySQL database to trace brute-force compromise, defacement, backdoor creation, and SQL data theft
access.logmysqlferoxbustert1110.003t1136.001
Windows DFIR
Examine a seized laptop with Autopsy and Signal decryption to determine whether a bomb threat is real, recovering encrypted messenger data
autopsyprefetchjumplistsqlitesignal
Reverse Engineering
Reverse three .NET malware samples with dnSpy and CyberChef to extract C2 addresses and identify the covenant framework behind them
dnspycyberchef.nett1219t1562
Network Forensics
Analyze a PCAP to uncover DNS exfiltration and encrypted covert HTTP C2, decrypting attacker commands and identifying the C2 framework
wiresharkdns-exfilpowershellt1048.003t1071.001
Incident Response
Correlate a PowerShell script, PCAP, and memory dump to trace an XMRig cryptominer infection, its persistence, and cryptomining IOCs
wiresharkvolatilitypowershellxmrigt1496
Cloud Security
Query AWS CloudTrail and S3 access logs to reconstruct an insider's over-permissive policy abuse and bucket data retrieval
cloudtrails3splunkjqinsider-threat
Windows DFIR
Use the dissect framework on a disk image to trace confidential data theft, USB exfiltration, and a reverse shell persistence chain
dissecte01usbregistryrecyclebin
AD / Kerberos
Trace an attacker from DVWA web compromise through AD lateral movement using Splunk and PCAP, uncovering credential dumping and pass-the-ticket
wiresharksplunksysmondvwapass-the-ticket
Reverse Engineering
Perform static disassembly of a malicious PE in Ghidra to map entry point, imports, anti-debug checks, mutex, and the decoded payload URL
ghidrape32isdebuggerpresentwininett1547.001
Network Forensics
Analyze network traffic to trace a webshell reverse shell and generate a JA3 fingerprint of the malware's C2 communication
wiresharkja3webshellt1046t1041
Malware Analysis
Research and analyze an Oski stealer sample with PEstudio and IDA to identify its C2, downloaded files, string cipher, and exfil config
pestudioidaprocmonvirustotaloski-stealer
Malware Analysis
Crack a builder archive and reverse a .NET ransomware sample, mapping its encryption, persistence, YARA detection, and leak-site IOCs
yarajohncyberchefdiepestudio
Network Forensics
Identify a spoofed PDF image, extract defanged URL IOCs, and hunt HTTP beacons in access logs to map compromised network hosts
access.logcyberchefpdfbeaconioc
Network Forensics
Analyze a pcap to trace an sqlmap SQL injection, credential theft, SSH privilege escalation, and encoded data exfiltration
wiresharksqlmappcapsqlissh
Malware Analysis
Perform dynamic analysis of a UPX-packed Discord token stealer to recover its PowerShell dropper, webhook URL, and exfil IOCs
sysinternalsupxprocmonpowershelldiscord
Log Analysis
Parse IIS web logs from the command line to isolate a malicious IP, geolocate it, and quantify its scanning and access activity
iis-logcliosintuser-agentt1584.006
Threat Intel
Correlate breach reports, adversary profiles, and malicious document IOCs to attribute a defacement and server attack to APT groups
exiftoolofficemalscannercyberchefosintshellcode
Malware Analysis
Analyze an RTF dropper and its .NET payload heaven.exe to recover the download URL, PE metadata, and C2 IP address
rtfdumpdnspydiehxdx64dbg
Malware Analysis
Unpack and disassemble a UPX-packed sample to uncover its anti-analysis checks, dropped payload, persistence keys, and YARA hits
idax64dbgyaraupxt1497.001
Incident Response
Trace ProcMon events to enumerate the commands malware used to disable Defender, clear audit policies, and wipe logs
procmonauditpolnetshset-mppreferencet1562
Malware Analysis
Extract IOCs from an ELF sample using exiftool, Zone.Identifier, and hash lookups to trace its download source and botnet family
exiftoolpowershellmalwarebazaarvirustotalzone.identifier
Incident Response
Review a rogue contractor's nmap and Metasploit artifacts to reconstruct scanning, exploitation, and blackmail payload delivery
nmapmetasploitsmbldapcyberchef
Windows DFIR
Combine a memory image, security logs, and registry hive to prove an insider accessed, compressed, and exfiltrated sensitive files
volatility2evtxtractusrclass.datregistryt1098
Memory Forensics
Analyze a memory dump to trace a malicious package download, masqueraded executable, stolen credentials, and data exfiltration
volatility3volatility2chromehistoryt1555.003t1567.004
Malware Analysis
Deobfuscate two malicious JavaScript droppers to reveal the Microsoft components, download URLs, and payloads they fetch
javascriptx64dbgcyberchefmsxml2base64
Windows DFIR
Timeline Windows event and Sysmon logs to reconstruct a DLL-hijack reverse shell, process injection, UAC bypass, and persistence
evtxecmdtimelineexplorersysmont1055t1134
Memory Forensics
Analyze a memory dump to find a vulnerable KeePass version and its CVE, then recover the malicious trigger that stole credentials
volatility3keepasssysinternalsnotepad++cve
Memory Forensics
Extract the viruskiller executable from a memory dump and analyze it to recover C2, hashes, PE details and registry persistence IoCs
volatilitypestudioresourcehackerautorunst1547.001
Memory Forensics
Recover a forum password from a RAM dump, download the insider's tool, decode obfuscated PowerShell shellcode and emulate it to find the C2 IP
volatilityspeakeasycyberchefshellcodepowershell
Windows DFIR
Trace a DLL injection into notepad.exe with Process Explorer and decode a base64 PowerShell reverse shell to identify the attacker's server IP
process explorercertutildll injectioncybercheft1059
Windows DFIR
Hunt timestomping anti-forensics in MFT output to expose masqueraded files, post-exploitation tooling and LSASS-dumping utilities on David's imaged machine
mfttimestompcsvcybercheft1070.006
Windows DFIR
Reconstruct a USB-borne ransomware breach using registry, shellbags and MFT artifacts to trace the disguised file, download URL and CVE exploited
registryusbstormftecmdshellbagst1486
Web Exploitation
Analyze Splunk SIEM logs to trace a Next.js middleware auth bypass, uploaded reverse shell and SSH lateral movement across the network
splunknextjsmiddleware-bypassauth.logcve
Malware Analysis
Detonate a PE32 sample under Sysmon and build detection logic by tracing its C2 domain, scheduled task, dropped bat file and persistence path
sysmondnseventscheduled-taskt1071.001t1053.005
Malware Analysis
Sift a large ProcMon capture to reconstruct a ransomware incident covering fileless PowerShell, service impact, Defender tampering and encryption
procmonransomwarepowerviewcybercheft1489
Network Forensics
Investigate RITA reports and Zeek logs to expose Nano's beaconing C2, cloud infrastructure and DNS TXT tunneling used to evade detection
ritazeekdns-tunnelingbeaconingta0011
Malware Analysis
Analyze an LNK dropper and cracked-software binary to uncover the certutil download, sandbox-evasion imports, user-agent and C2 endpoint
pestudiodetect-it-easyapi-monitorlnkcertutil
Memory Forensics
Reverse-engineer BlackEnergy 2 from a memory image using malfind and ssdt to find injected code, hooked SSDT functions and the malicious rootkit driver
volatilitymalfindssdtblackenergyrootkit
Malware Analysis
Dissect a malicious OneNote attachment hiding an RTLO-disguised HTA to recover the embedded payload and files it downloads to disk
onenotertlohtacyberchefpowershell
Incident Response
Trace a Kimsuky-style intrusion across DC and workstation artifacts covering Sliver C2, LSASS dumping, process injection and DC lateral movement
hayabusasysmonsliverlsasst1566.001
Mobile Forensics
Unpack a malicious macOS .pkg to expose its curl download, credential and PEM-file theft, exfiltration URL and installer persistence mechanism
macospkgunarcpiot1552.004
Malware Analysis
Carve hidden streams from two JPEG samples with jpegdump to identify an embedded c99 PHP webshell and a malware payload's C2 endpoint
jpegdumpcyberchefwebshellphpc99
Cloud Security
Investigate an AWS and AD breach by dumping leaked git keys and pivoting through Splunk to trace ASREPRoast, obfuscated commands and lateral movement
splunkawsgitdumperasreproastt1566
Web Exploitation
Trace a WordPress defacement through access and MySQL logs, tracking WPScan enumeration, sqlmap injection, and a malicious plugin web shell
wpscansqlmapaccess.logwordpresscve-2024-2879
Windows DFIR
Analyze Sysmon events and a pcap to reconstruct a PrintNightmare exploit that transfers a malicious DLL over SMB and spawns a reverse shell
printnightmarewiresharksysmonsmbrundll32
Windows DFIR
Examine process-tree snapshots to spot masquerading and anomalously located system processes using Windows process genealogy
pslistprocess-treelsasssvchostt1055
Malware Analysis
Deobfuscate a VBScript dropper to reveal its WebClient staging call, C2 URL, and PowerShell download-and-execute payload path
vbscriptdeobfuscationpowershellwebclientt1027
Cloud Security
Query CloudTrail and Azure logs in Splunk to trace a threat actor pivoting across a hybrid AWS/Azure environment to exfiltrate and deface data
splunkcloudtrailawsazures3
Malware Analysis
Automate sample triage with the LiSa sandbox to profile an ELF binary's C2 and analyze a PCAP revealing scans and a 2021 exploit attempt
lisasandboxurlhausvirustotalpcap
Incident Response
Use Splunk over Sysmon logs to follow a phishing-borne compromise from a malicious document through persistence to AD credential dumping
splunksysmoncertutilmimikatzdcsync
Email / Phishing
Triage a phishing email in Thunderbird and CyberChef to extract sender, attachment, embedded URL, and MITRE phishing sub-techniques
emlthunderbirdcyberchefbase64t1566.001
AD / Kerberos
Carve an AD snapshot from a disk image with FTK Imager and AD Explorer to enumerate OUs, user attributes, GPO policies, and LAPS settings
ftk-imagerad-explorerlapsntdsgpo
Network Forensics
Reconstruct an attacker's chain in Arkime as they SQL-inject a surveillance console and pull a CCTV clip from S3 via a presigned URL
arkimepcapsql-injections3presigned-url
Windows DFIR
Recover deleted concept-art evidence from thumbcache and iconcache databases to prove leaked plans once resided on the suspect's laptop
thumbcacheiconcachethumbcache-viewermd5reverse-image
Network Forensics
Analyze a PCAP in Wireshark to trace router firmware exploitation, identifying the CVE, injected parameter, and reverse-shell commands
wiresharktsharkpcaprouterreverse-shell
Memory Forensics
Perform Linux memory analysis with Volatility 3 to recover the victim's bash history, payloads, and SCP transfers from the attack
volatility3linuxbash-historyscpt1059.006
Malware Analysis
Dynamically analyze NG-IA.exe by emulating its C2 to extract dropped DLLs, LOLBAS execution, scheduled-task persistence, and registry keys
procmonwiresharklolbasc2-emulationscheduled-task
Windows DFIR
Investigate a disk image in Autopsy and PeStudio to trace a downloaded malicious file, its C2 protocol, persistence, and originating email
autopsypestudiocyberchefentropypersistence
Network Forensics
Dissect a PCAP in Wireshark to collect IOCs from a trojan download, profiling the victim host and decoding stolen credentials exfiltrated over SMTP
wiresharktcpdumpcyberchefsmtpt1566
Linux DFIR
Investigate a compromised Ubuntu corporate wiki using memory, disk, and pcap to trace a CVE exploit, webshell, and database exfiltration
volatilityautopsywebshellpcapjd-gui
Malware Analysis
Analyze malicious Excel XLM macros with oletools and LibreOffice to reveal obfuscated payload download URLs and rundll32 execution
olevbaoletoolsxlm-macrorundll32libreoffice
Incident Response
Trace an ISO-delivered in-memory loader from execution artifacts through C2 beaconing, process injection, and Active Directory enumeration
shellbaguserassistpestudioc2process-injection
Windows DFIR
Perform full triage-image DFIR to trace a drive-by PowerShell payload, shellcode C2 callback, and persistence executable
ez-toolsidashellcodec2persistence
LetsDefend
LetsDefend → LetsDefend Challenge
LETSDEFEND · 71
AD / Kerberos
Parse DC and workstation Security logs and prefetch to trace an AS-REP roasting attack and the compromised account's subsequent activity
as-repkerberosevtxecmdpecmdprefetch
Reverse Engineering
Reverse engineer the .NET Agniane infostealer with ILSpy/dotPeek to recover its decoded hostname, anti-debug APIs, and Telegram exfil bot
agnianestealer.netilspyanti-analysis
Reverse Engineering
Reverse engineer the .NET AstasiaLoader that fetches a URL from a GitHub README to drop RedLine stealer and exfiltrate data to Telegram
astasialoader.netredlinedotpeekdetect-it-easy
Malware Analysis
Analyze a Windows batch script that uses bitsadmin LOLBIN to download, unzip, and execute Laplas Clipper malware from a C2 server
batchbitsadminlolbinlaplas-clippervbscript
Network Forensics
Investigate a compromised web server by correlating pcap and auth logs to uncover HTTP, RDP, and SSH brute-force attacks and valid credentials
wiresharkrdpbrute-forceauth.logpcap
Network Forensics
Analyze a pcap of an Openfire chat server exploited via CVE-2023-32315 path traversal to trace admin creation and webshell plugin upload
cve-2023-32315openfirewiresharkwebshellpath-traversal
Network Forensics
Investigate pcap and logs from a compromised water-treatment PLC to identify the exposed service, brute-force entry point, and attacker actions
icsplcwiresharkbrute-forcepcap
Network Forensics
Trace an attacker's port scan and PJL abuse of an HP network printer in a pcap to determine exploited ports and stolen print jobs
wiresharkpjlport-scanprinterpcap
Linux DFIR
Investigate a UAC triage image of a Confluence server exploited via CVE-2023-22527 SSTI, using access and Sysmon logs to reconstruct attacker commands
cve-2023-22527confluenceuacsysmonssti
Malware Analysis
Decompile a .NET PE64 infostealer with dotPeek to uncover its anti-analysis VirusTotal checks, data-gathering commands, and Discord webhook C2
dotpeekdetect-it-easyinfostealerwmicdiscord-webhook
Network Forensics
Reconstruct SMTP email conversations from a pcap and extract an attachment with NetworkMiner to disclose a leaking agent's identity and meetup
smtpwiresharknetworkminerpcapemail
Windows DFIR
Trace a malware entry point on a KAPE-acquired image by parsing Windows Live Mail and Discord cache to identify the attacker and first contact
kapediscordchromecacheviewwindows-live-mailcache
Reverse Engineering
Reverse a Visual C++ downloader binary in IDA to recover the C2 IP, user-agent, downloaded payload, and WinHTTP request functions
idadetect-it-easywinhttpc2payload
Email / Phishing
Analyze a phishing email header and its EXE attachment with pestudio and VirusTotal to confirm a malicious Loki infostealer payload
emlpestudiovirustotallokiphishing
Malware Analysis
Analyze a malicious Excel 4.0 XLM macro document that abuses Auto_Open and regsvr32 to fetch and execute a second-stage DLL payload
xlm-macrosregsvr32xlmmacrodeobfuscatorauto-openc2
Malware Analysis
Dissect a Go-based Kuiper ransomware sample in Ghidra and IDA to recover its base64-encoded PowerShell process-killer and evasion techniques
golangransomwareghidraidapowershell
AD / Kerberos
Trace a Golden Ticket attack against a Domain Controller by parsing Security.evtx with EvtxECmd to identify the compromised service account and lateral movement
golden-ticketevtxecmdkerberosevent-4624pass-the-hash
Network Forensics
Examine a pcap to enumerate HTTP GET requests and recover the server software, OpenSSL version, and Basic Authentication credentials
pcapwiresharkhttpbasic-authcredentials
Malware Analysis
Follow an IcedID infection chain from a macro-laden Word dropper through mshta and rundll32 to the installer DLL and its C2 host
icedidolevbamshtarundll32hta
Malware Analysis
Extract a PowerShell payload hidden in a PNG via Invoke-PSImage steganography, revealing embedded Mimikatz executables and their hashes
steganographyinvoke-psimageexiftoolmimikatzpowershell
Network Forensics
Perform root-cause analysis on a Cobalt Strike infection pcap using Wireshark and NetworkMiner to trace DocuSign phishing delivery and C2 traffic
cobalt-strikewiresharknetworkminerpcapc2
Log Analysis
Investigate web server logs to reconstruct a Nikto scan, login brute force, code injection via whoami, and attacker persistence
niktoweb-logsbrute-forcecode-injectionpersistence
Reverse Engineering
Decompile a malicious Java archive with JD-GUI to analyze JNA-based shellcode injection targeting native Windows processes via kernel32
javajd-guijnashellcodeprocess-injection
Linux DFIR
Investigate a UAC-collected Linux forensic image to identify a kernel privilege-escalation exploit run from /tmp and trace the attacker's process
uacprivilege-escalationkernel-exploitvirustotalprocess
Malware Analysis
Analyze a Kimsuky APT VBScript sample to map its WMI reconnaissance, antivirus enumeration, registry tampering, and C2 exfiltration functions
kimsukyvbscriptwmiregistryapt
Linux DFIR
Examine a Linux disk image to identify a cracked-software ELF malware that uses strings and netcat to exfiltrate Chrome data to an attacker IP
stringselfnetcatauth.logexfiltration
Linux DFIR
Mount a Linux disk image and trace a disgruntled ex-employee's activity through bash_history, apt logs, auth.log and a hidden secret file
bash_historyauth.logaptfstabmd5sum
Memory Forensics
Examine a Linux memory dump with Volatility to recover the kernel version, a dropped PHP web shell, and the attacker's reverse-shell IP and port
volatilitylinux_bashbannersreverse-shelldocker
Memory Forensics
Analyze a memory dump of a LockBit ransomware infection to pinpoint the malicious process, encryption extension, ransom note and registry persistence
volatilitylockbitransomwarepstreevirustotal
Log Analysis
Investigate an endpoint breach through Sysmon logs in Splunk to reconstruct the reverse shell, fodhelper UAC bypass and dropped Mimikatz
sysmonsplunkfodhelperuac-bypassmimikatz
Malware Analysis
Use Oletools oleobj on malicious Office documents to extract embedded C2 indicators and confirm exploitation of the CVE-2021-40444 MSHTML flaw
cve-2021-40444mshtmloletoolsoleobjdocx
Malware Analysis
Analyze a packed AutoIt executable with Detect It Easy and AutoIt-Ripper to unpack the script and reveal its payload-download domain
autoitdetect-it-easyentropyautoit-rippervirustotal
Windows DFIR
Examine a Windows disk image to identify a malicious cookie-stuffing Chrome extension by its ID, name and attacker domain
chrome-extensionmanifest.jsoncookie-stuffingchrome-statsosint
Malware Analysis
Analyze a weaponized RTF document exploiting CVE-2017-11882 to identify the C2 server, downloaded payload and dropped aro.exe
cve-2017-11882rtfvirustotalanyrunc2
Malware Analysis
Decode obfuscated VBA macro strings with CyberChef to reveal the payload download URL, HTTP method, user-agent and WMI persistence object
vbamacrocyberchefobfuscationwmi
Network Forensics
Trace a web attack in a pcap through brute-force, an XXE source-code leak and LFI reading /etc/passwd to reconstruct the intrusion chain
wiresharkpcapxxelfibrute-force
Network Forensics
Analyze pcap traffic of a WordPress compromise to track wpscan enumeration, credential brute-forcing and RCE via a vulnerable plugin
wiresharkpcapwpscanwordpressbrute-force
Memory Forensics
Use Volatility 3 on a Windows memory dump to spot a masquerading lsass, identify winPEAS and crack the compromised user's NT hash with John
volatility3pstreewinpeashashdumpjohn
Windows DFIR
Parse a jump server's $MFT with MFTECmd and MFTExplorer to recover a downloaded file, its source URL via Zone Identifier and creation timestamps
mftecmdmftexplorermftzone-identifierntfs
Malware Analysis
Deobfuscate a comment-bloated JavaScript dropper to reconstruct its real logic and expose the WScript network and WMI objects it abuses
javascriptdeobfuscationwscriptwmiscripting
Reverse Engineering
Decompile a .NET DarkCrystal RAT with dotPeek and ILSpy and script TripleDES decryption to recover its C2 server URL and port
dnspyilspydotpeektripledesdarkcrystal
Network Forensics
Filters a pcapng capture in Wireshark to trace an HTTP file upload between two hosts and recover an exfiltrated encryption script.
wiresharkpcaptcp-streamhttpfile-extraction
Malware Analysis
Uses the Didier Stevens PDF suite and peepdf to unpack a malicious PDF's OpenAction, embedded JavaScript, and base64 PowerShell payload.
pdfidpdf-parserpeepdfpowershellbase64
Windows DFIR
Images a compromised disk with FTK Imager and mines Edge browser databases and registry hives to trace a malicious PDF's PowerShell execution.
ftk imagerpdfstreamdumperregistryedge artifactspowershell
Web Exploitation
Reviews Apache configuration and access logs to confirm exploitation of the PHP-CGI argument injection RCE against a web server.
cve-2024-4577php-cgiapacheaccess.logrce
Email / Phishing
Parses a German PayPal-themed phishing email's headers and embedded links, confirming the malicious URL via VirusTotal.
emlphishingvirustotalemail-headerurl-analysis
Network Forensics
Applies Wireshark TCP flag filters and passive OS fingerprinting to identify a scanning host and the systems it discovered on the network.
wiresharkpcapport-scantcp-flagsos-fingerprinting
Malware Analysis
Statically reverses a PowerShell keylogger's functions to map its Tor-based C2 channel, screenshot capture, and keystroke logging.
powershellkeyloggertorsocks5c2
Malware Analysis
Decodes a base64-obfuscated PowerShell one-liner in CyberChef to expose its malicious download-and-execute behavior.
cyberchefbase64powershellobfuscation
Malware Analysis
Leverages VirusTotal's behavior and relations tabs to profile a malicious PowerPoint file's dropped HTML file and mshta persistence chain.
virustotalpptmshtadropped-filessandbox
Windows DFIR
Correlates Suricata alerts in Brim with a Redline memory dump to trace a PrintNightmare privilege-escalation exploit to the attacker's SMB share and DLL.
cve-2021-34527redlinebrimsuricatamemory-forensics
Email / Phishing
Dissects a phishing email's malicious OneNote attachment to trace its embedded HTA lure and registry-key creation used to deliver QakBot.
onenotehtaphishingqakbotregistry
Memory Forensics
Mines a Redline memory dump for a sideloaded malicious DLL masquerading inside a Windows process to uncover a ransomware infection chain.
redlinememory-dumpdll-sideloadingransomwarevirustotal
Windows DFIR
Parses SYSTEM, SAM, SOFTWARE, and SECURITY registry hives with RegRipper and Registry Explorer to reconstruct host and user configuration details.
regripperregistry explorersamsystem hive
Malware Analysis
Sandboxes a macro-laden Excel stager in VirusTotal and Triage to trace its dropped files and second-stage payload download URL.
virustotaltriagevba-macroxlsmstager
Reverse Engineering
Decompiles a .NET Revenge RAT sample with dotPeek to extract its mutex, C2 configuration, host fingerprinting, and anti-sleep routines.
dotpeek.netmutexc2rat
Reverse Engineering
Decompiles a .NET information stealer to map its VirusTotal-evasion checks, UAC bypass commands, and targeted wallet and file-extension lists.
dotpeek.netuac-bypassinfostealeranti-vm
Network Forensics
Analyze a pcap in Wireshark to trace a Shellshock exploit against an Apache/Ubuntu server and recover the attacker's command
wiresharkpcapshellshockapachehttp
Malware Analysis
Unpack and inspect a malicious Chrome CRX extension with ExtAnalysis and crxcavator to identify its metadata and scripts
crxmanifest.jsonextanalysischromecrxcavator
Windows DFIR
Investigate a malicious PyPI-style package by parsing MFT, UsnJournal, and browser artifacts to trace credential exfiltration to a C2
mftecmdusnjournalcyberchefsetup.pychrome
Windows DFIR
Reconstruct an unauthorized TeamViewer remote session from connection logs to identify the intruder, session IDs, and durations
teamviewerlog-analysisremote-accessconnectionstriage
Malware Analysis
Reverse the .NET TinyTurla backdoor to map its RunShell, command polling, and MSBuild in-memory execution capabilities
tinyturla.netmsbuildc2s0668
Malware Analysis
Analyze the UPSTYLE Python backdoor exploiting CVE-2024-3400 to reveal its log-monitoring command execution and self-restoring persistence
upstylecve-2024-3400globalprotectpythonbackdoor
Memory Forensics
Combine memory and disk forensics with Volatility, oledump, and Outlook OST analysis to trace a WannaCry infection back to a phishing email
volatilitywannacryoledumpftk-imagerphishing
Memory Forensics
Use Volatility 3 and CyberChef to analyze a WinRAR CVE-2023-38831 exploit in a memory dump and decode its PowerShell download chain
volatilitycve-2023-38831winrarcyberchefpowershell
Memory Forensics
Use Volatility 3 and IDA to trace a fake crack tool that drops BlackCat ransomware and modifies registry keys in a memory image
volatilityfilescanidablackcatransomware
Windows DFIR
Examine SAM, SOFTWARE, SYSTEM, and NTUSER registry hives in Registry Explorer to profile added users, OS build, network config, and executed files
registrysamntuser.datamcacheregistry-explorer
Network Forensics
Investigate CVE-2024-21320 theme spoofing by analyzing SMB and NTLMSSP traffic to recover the attacker share and relayed NTLM hashes
cve-2024-21320ntlmsmbwiresharkkape
Malware Analysis
Dissect a YARA rule detecting the GwisinLocker Linux ransomware using IDA disassembly and hunt matching samples on Hybrid Analysis
yaragwisinlockeridahybrid-analysiself
Reverse Engineering
Reverse engineer a Linux ELF cl0p ransomware sample in IDA to extract its encryption key, target directories, extension, and ransom note
cl0pransomwareelfidadetect-it-easy
Reverse Engineering
Reverse engineer a macOS infostealer in Ghidra and IDA to map its targeted browsers, crypto wallets, Telegram exfil channel and HTTP C2
ghidraidamacosinfostealercrypto-wallet
HTB Sherlocks
HackTheBox → HTB Labs → HTB Sherlocks
HTB · SHERLOCK · 52
Network Forensics
Reconstruct an APT intrusion from PCAP in Wireshark, tracing port scanning, DNS zone transfer, credential brute force, initial access, privesc, and persistence
wiresharkpcapdns-zone-transferport-scanreverse-shell
Memory Forensics
Analyze a Linux memory dump with Volatility to uncover a hidden malicious kernel module masquerading as nfnetlink that hooks syscalls and hides processes
volatilitylinuxrootkitkernel-modulesyscall-hook
Windows DFIR
Parse the NTFS MFT with MFTECmd and Timeline Explorer to trace a downloaded ZIP, identify a resident invoice.bat stager, and recover its C2 IP and port
mftecmdmfttimeline-explorerzone-identifierhex-editor
Memory Forensics
Analyze a memory image with Volatility to find a malicious startup process, then reverse the malware's mutex, anti-debug tricks, and DGA C2 domains
volatilitymalwaredgaanti-debugvirustotal
Linux DFIR
Investigate Unix auth.log and wtmp to trace an SSH brute-force, identify the compromised account, backdoor user, and privilege escalation
auth.logwtmpsshutmpdumpbrute-force
Log Analysis
Trace an insider contractor through phpBB SQLite tables and access.log to uncover a credential-stealing XSS post and stolen database backup
access.logsqlitephpbbxssldap
AD / Kerberos
Correlate DC security logs, PowerShell logs, and Prefetch to detect a kerberoasting attack executed via PowerView and Rubeus
kerberoastingrubeuspowerviewprefetchpecmd
AD / Kerberos
Examine domain controller security logs to detect an AS-REP roasting attack, identifying the targeted account, its SID, and the compromised asset
asrep-roastingkerberosevent-4768t1558.004sid
Network Forensics
Examine a pcap in Wireshark to trace a Pikabot infection, extract the PE payload, and analyze self-signed TLS certs and tunneling domains
wiresharkpcappikabottlsself-signed
OSINT
Extract timestamps from memory-recovered URLs with unfurl and use OSINT to expose an insider threat and the threat actor handler behind data exfiltration
unfurlexiftoolurl-analysisinsider-threatpdf
Windows DFIR
Analyze a suspect's disk image to recover Zoom conferencing artifacts, DPAPI-protected credentials, and encrypted meeting data revealing a planned attack
registryuserassistprefetchzoomdpapi
AD / Kerberos
Analyze DC system and security logs to detect vssadmin abuse creating a volume shadow copy and dumping NTDS.dit with a registry hive
ntds.ditvssadminevent-7036event-4799esent
AD / Kerberos
Trace ntdsutil.exe abuse through DC event logs to identify the dumped NTDS database path, enumerated privilege groups, and the malicious logon session
ntds.ditntdsutilevent-325event-327esent
Windows DFIR
Analyze Edge history and MFT to trace a fake AI-tool malvertising install, uncovering the staging directory and recovering the malicious JS payload
edge-historymftecmdtimeline-explorerregistrymalvertising
Malware Analysis
Reverse a PowerShell-to-PE binary with pestudio and strings to recover the reversed-base64 script, network IOCs, and exfiltration password
pestudiops2exebase64stringsexfiltration
Cloud Security
Correlate web access logs and AWS CloudTrail to trace an SSRF-driven metadata compromise, stolen IAM credentials, and database snapshot exfiltration
cloudtrailssrfawsiamaccess.log
Windows DFIR
Triage a single MFT record with MFTECmd and MFTExplorer to identify a phished user's malicious HTA download, its ADS ZoneId, and file sizes
mftmftecmdmftexplorerzone-identifierhta
Windows DFIR
Parse the Windows Notifications database in DB Browser to reconstruct an insider's Slack chat revealing data leaked to a rival company for money
notifications-dbsqliteslackinsider-threatunix-time
Incident Response
Analyze API Monitor apmx64 logs to track WSL2 activity, uncovering intercepted string functions, exfiltrated files, and lsassy credential theft
wsl2api-monitorapmx64api-hookinglsassy
Network Forensics
Analyze a packet capture to trace how an attacker port-scanned, brute-forced FTP, and used port knocking to reach a critical Forela dev service
pcapwiresharkport-scanftpport-knocking
Network Forensics
Investigate a PCAP of DNS-tunneled C2 traffic, decoding queries to recover attacker commands and quantify stolen customer PII records
pcapdns-tunnelingwiresharktsharkcyberchef
Malware Analysis
Reverse-engineer a Linux ransomware binary in Ghidra to recover the encryption key and decrypt Forela's ransomed UNIX server files
ransomwareghidrareverse-engdecryptionlinux
Windows DFIR
Analyze Windows event logs to track a user's malicious logon, firewall tampering, scheduled task, PowerShell activity, and log clearing
evtxevent-logs46244698defender
Network Forensics
Examine PCAP and logs to confirm a Bonitasoft auth-bypass RCE (CVE-2022-25237) via credential stuffing and SSH key persistence
pcapbonitacve-2022-25237credential-stuffingrce
Web Exploitation
Trace log evidence of a Next.js middleware bypass (CVE-2025-29927) chained with SSRF and Redis exploitation against BCI infrastructure
nextjscve-2025-29927middleware-bypassssrfredis
Windows DFIR
Reconstruct a data-extortion attack from Notepad++ artifacts to recover the attacker's exfil archive, crypto wallet, and contact details
notepad++config.xmlsessions.xmlextortionexfiltration
Network Forensics
Hunt an LLMNR poisoning attack in a PCAP, identifying the rogue Responder host and stitching NTLM values to crack the victim's password
llmnrntlmresponderwiresharkntproofstr
Cloud Security
Investigate AWS CloudTrail logs in Splunk to track compromised access keys, IAM privilege escalation, and S3 data encryption by a threat actor
awscloudtrailsplunks3iam
Windows DFIR
Trace a malicious NuGet supply-chain package across PowerShell history, browser, and MFT artifacts to its Defender-disabling C2 payload
nugetmftecmdpsreadlinesupply-chaindefender
Cloud Security
Correlate Windows artifacts and AWS CloudTrail logs to track a rogue insider abusing Ammyy Admin and tampering with an S3 archive
cloudtrails3awsammyyamcache
Web Exploitation
Investigate pcap, auth.log, and bash history to trace an AI chatbot prompt-injection leading to credential leak and root privilege escalation
pcapwiresharkauth.logprompt-injectioncve
Reverse Engineering
Reverse a malicious NSIS/Electron Node.js keylogger, decoding XOR shellcode and V8 bytecode to recover its exfil channel and fake coupon
nodejselectronasarshellcodexor
Incident Response
Correlate KAPE logs and a memory dump to track RDP access, Defender bypass, privilege escalation, and exploit use on a Windows 11 host
kapememory-dumprdpamsi-bypassprivesc
Incident Response
Follow prefetch and event-log evidence to trace BITS downloads, credential dumping, and database exfiltration during lateral movement
kapeprefetchbitsadmint1197mimikatz
Windows DFIR
Audit an insider elf's workstation and eM Client emails to reconstruct threat-actor contact and locate Santa's exfiltrated secret file
kapeemclientmftusn-journalemail
Cloud Security
Audit AWS CloudTrail logs to confirm automated S3 bucket theft, identify malicious IPs, and pinpoint the leaked VPN file and compromised account
awscloudtrails3splunkuser-agent
Memory Forensics
Analyze a memory dump with Volatility to trace an LNK/VBS infection chain, process injection, and procdump credential theft on a workstation
volatilitymemory-dumplnkvbsshellcode
Network Forensics
Analyze a printer-server pcap in Wireshark to trace port scanning, PJL print jobs, and lateral movement to a critical SSH server
wiresharkpcappjlprinterssh
Windows DFIR
Investigate a KAPE triage of a compromised domain controller to trace CVE exploitation, a malicious service, and file-encrypting ransomware
kapemftecmdusn-journalransomwarerbcmd
Windows DFIR
Trace a phishing LNK that abuses LOLBins to stage C2, then reconstruct the attacker's VPN and RDP access from Windows artifacts
lnkprefetchpecmdrdp-cachelolbin
Windows DFIR
Reconstruct a fake-captcha ClickFix attack from RunMRU, PowerShell history, and network traffic to recover the downloaded stager and reverse shell
runmruregistrypowershellfake-captchac2
Linux DFIR
Examine CatScale Linux artifacts and bash history to trace a trojanized enum script that downloads a password-protected payload and sets cron persistence
catscalebash-historycronwgetpersistence
AD / Kerberos
Correlate a network capture with logon audit logs to detect an NTLM relay attack from a rogue device authenticating as a stolen account
ntlm-relaywiresharksmbnbnsevent-log
Memory Forensics
Analyze a memory dump and disk image to trace a malicious VSCode extension spawning a NjRAT reverse shell and modifying the registry for persistence
volatilitypstreenetstatftk-imagervscode
Memory Forensics
Analyze a memory dump with Volatility malfind and dumpfiles to identify a process-hollowing C2 implant and build the incident timeline
volatilitymalfindpstreedumpfilesc2
Network Forensics
Trace a pcap from a malicious VBS download through PowerShell and AutoHotkey staging to identify the delivered RAT and its C2
wiresharkpcapvbssmbautohotkey
Windows DFIR
Investigate KAPE artifacts and Sysmon to trace a TeamViewer social-engineering intrusion deploying Merlin C2 and time-tampering PowerShell scripts
sysmonkapeteamviewerpowershellbitlocker
Windows DFIR
Parse prefetch and USN journal artifacts to count PsExec executions and identify the service binary, key file, and named pipe from lateral movement
psexecprefetchpecmdusn-journalmftecmd
Network Forensics
Analyze HTTP POST traffic to reconstruct a router web-admin brute force and command-injection CVE exploit leading to a reverse shell C2
wiresharkpcapcommand-injectionroutercve
Web Exploitation
Investigate CatScale logs from a WordPress server to trace a WPScan fingerprint, Ultimate Member CVE exploit, backdoor user, and web shell RCE
wordpresscatscaleaccess.logwpscanwebshell
Windows DFIR
Examine Sysmon logs to identify an msiexec-delivered backdoored UltraVNC installer, its timestomping, dropped files, and C2 connections
sysmonevent-id-1msiexectimestompingultravnc
Windows DFIR
Trace an insider's USB data theft from an FTK disk image using SYSTEM/SOFTWARE hives to recover device, timestamps, and copied files
usbregistryftk-imagerregexplorersystem-hive
TryHackMe
TryHackMe → THM Blue Teaming
TRYHACKME · 33
Linux DFIR
Investigate an Ubuntu API server breach where command injection in an Nginx-served Python app led to SSH access and data exfiltration
nginxcommand-injectionsshaccess.logtelegram
Log Analysis
Hunt through Splunk process-execution (4688) logs to spot an imposter account, malicious scheduled tasks, and LOLBIN payload downloads
splunkevent-4688schtaskscertutillolbin
Windows DFIR
Analyze three compromised servers using EvtxECmd and RDP logs to backtrack lateral movement and persistence from the Midnight Blizzard group
evtxecmdrdpevent-1149timeline-explorerpersistence
Network Forensics
Decrypt SMB3 traffic in a pcap using NT hashes recovered from an LSASS dump to prove which fired employees accessed private files
wiresharkpypykatzlsasssmb3ntlm
Incident Response
Assess a phishing compromise across email headers, endpoint execution, and network traffic to trace the Boogeyman actor's malicious attachment
email-headerdkimphishingwiresharkpowershell
Email / Phishing
Decode a base64 email attachment and analyze headers to assess a spear-phishing resume that compromised an HR specialist's workstation
emlemail-headerbase64cyberchefmalicious-doc
Incident Response
Reconstruct a multi-stage ISO/HTA intrusion in Kibana and Sysmon logs, tracing DLL execution, persistence, and threat-actor activity
kibanasysmonhtarundll32iso
Network Forensics
Analyze a pcap in Wireshark to trace a malicious Word document download, C2 domains, and outbound connections from an infected workstation
wiresharkpcaphttpdnsc2
Memory Forensics
Follow an artefact trail across a memory dump and disk image with Volatility and FTK Imager to uncover a netcat reverse shell
volatilitypstreenetcatftk-imagerreverse-shell
Linux DFIR
Review auth.log and bash history to trace a disgruntled IT employee's privileged commands, rogue user creation, and sudo changes
auth.logbash_historysudovisudocron
Windows DFIR
Use Autopsy to extract host details, user accounts, network config, and IP/MAC from an E01 disk image and its registry hives
autopsye01registryftk-imagerdisk-image
Windows DFIR
Use Autopsy and registry artifacts to trace a terminated engineer's USB exfiltration, hotspot evasion, and accessed sensitive files
autopsyusbstorregistryuebaexfiltration
Disk Forensics
Repair a corrupted MBR boot signature, examine partitions, and carve deleted files to prove an insider stole quantum-crypto research
ftk-imagerautopsyhxdmbrfile-carving
Linux DFIR
Examine a suspect's Linux workstation using wtmp, auth.log, and syslog to trace logins, USB insertion, and data exfiltration activity
wtmpauth.logsyslogusblast
Threat Hunting
Hunt through Elastic and Sysmon logs to trace a malicious ZIP attachment from download to data exfiltration on a finance workstation
elasticsysmonkibanaphishingexfiltration
Log Analysis
Query Splunk Windows event logs to detect a masqueraded backdoor user, registry changes, and remote WMI account creation
splunksysmonwmi4720powershell
Linux DFIR
Perform a compromise assessment on a Linux honeypot to uncover a backdoor account, cron persistence, and hidden malicious processes
passwdcronpersistencekeyloggerelf
Network Forensics
Analyze HTTP connection logs in Kibana to trace bitsadmin LOLBin C2 activity and recover a malicious file from a filesharing site
kibanaelasticbitsadminlolbinc2
Log Analysis
Analyze web server logs to reconstruct an attacker's toolchain, vulnerable endpoints, and stolen data from a breached juice shop
access.lognmaphydrasqlmapsql-injection
Memory Forensics
Use Volatility across multiple memory dumps to recover a password, console history, shutdown time, and a TrueCrypt passphrase
volatilityhashdumpconsolestruecryptvmem
Threat Hunting
Sift Splunk Sysmon events to find NirSoft credential-viewer binaries and activity while endpoint security was disabled
splunksysmonnirsofteventcode-1credential-theft
Log Analysis
Investigate Splunk Sysmon logs to trace a base64 PowerShell dropper, Defender tampering, and scheduled-task persistence in a ransomware case
splunksysmonpowershellbase64scheduled-task
Email / Phishing
Investigate an .eml file's headers and client-side body to determine whether a ParrotPost login request is a credential-stealing phish
emlemail-headersmimespfcredential-theft
Email / Phishing
Use Thunderbird and CyberChef to dissect phishing email headers and bodies, extracting spoofed senders, origin IPs, and malicious URLs
emlthunderbirdcyberchefemail-headersdefang
Incident Response
Use Redline to analyze an infected host and identify the REvil ransomware binary, its download URL, hash, and files it encrypted
redlinerevilransomwaremd5virustotal
Windows DFIR
Investigate a live Windows host with Sysmon and Event Viewer to reconstruct a fake-antivirus ransomware execution and its aftermath
sysmonevent-viewerransomwarefake-avtimeline
Windows DFIR
Examine registry hives with Registry Explorer and RegRipper to prove secret recipe files were copied onto a suspect's machine
registryregistryexplorerregrippersamez-tools
Log Analysis
Investigate ModSecurity WAF logs in Kibana to build a timeline of scanning, brute-force, and data exfiltration against an e-commerce server
elastickibanamodsecuritygobusterhydra
Email / Phishing
Analyze phishing emails and a recovered phishing kit to trace the adversary's redirect URLs, .zip archive, and threat intel
phishingcyberchefthunderbirdphishing-kitcti
Linux DFIR
Hunt and remediate five backdoors on a compromised Linux server, uncovering malicious binaries and .bashrc persistence
linuxsshbackdoorbashrcpersistence
Windows DFIR
Reconstruct a full intrusion from a malicious document through privilege escalation using Sysmon, event logs, and packet captures
sysmonevtxpcaptimeline-explorermaldoc
Email / Phishing
Inspect a suspicious business email's headers, SPF/DMARC records, and originating IP to determine if it is a phishing attempt
phishingemail-headersspfdmarcmxtoolbox
Windows DFIR
Investigate insider activity on a live Windows system to identify searched, accessed, and exfiltrated files during an absence window
registrywordwheelqueryautopsykapeexfiltration
HTB Machines
HackTheBox → HTB Labs → HTB Machines → VulnLab
HTB · MACHINE · 16
AD / Kerberos
Pull passwords from LDAP descriptions via null session, reset a hidden user, then use Backup Operators to dump NTDS and root the DC
ldapnull-sessionbackup-operatorsntds.ditsecretsdump
AD / Kerberos
Abuse a guest account and SYSVOL logon script for a foothold, then chain WriteOwner and GPO abuse to root the domain controller
guest-accountlogon-scriptsysvolgpo-abusebloodhound
AD / Kerberos
Steal a hash with a guest-writable share, Kerberoast svc_mssql, forge a silver ticket for xp_cmdshell, then abuse SeImpersonate for SYSTEM
ntlm_theftkerberoastingsilver-ticketxp_cmdshellseimpersonate
Web Exploitation
Exploit Grafana directory traversal (CVE-2021-43798) to steal and crack DB hashes, then abuse sudo docker exec privileged mode to reach root
grafanacve-2021-43798dockerhashcatlfi
Web Exploitation
Deploy a malicious LimeSurvey plugin for a Docker foothold, harvest an env-var password, and abuse a shared host directory with SUID bash to root the box
limesurveyphp-shelldockermysqlsuid
Windows Privesc
Phish a malicious macro ODT over SMTP for a shell, abuse developer webroot control for a webshell, then leverage SeImpersonatePrivilege to reach SYSTEM
odtphishingsmtpwebshellseimpersonate
Windows Privesc
Recover a Gitea PAT to deploy an ASPX webshell, decrypt mRemoteNG credentials for RDP, then exploit PDF24 Creator CVE-2023-49147 via oplock to reach SYSTEM
giteaaspx-shellmremotengcve-2023-49147rdp
Web Exploitation
Abuse an unauthenticated JMX MBean server for a Tomcat foothold, loot a backup with SSH keys, then create an admin user via sudo to become root
jmxmbeantomcatbeanshootermetasploit
Windows Privesc
Force NTLM auth with an ntlm_theft WAX file for SSH access, abuse a symlink upload for a webshell, then use FullPowers and SeImpersonate to reach SYSTEM
ntlm_theftwaxaspx-shellsymlinkfullpowers
Web Exploitation
Abuse forgot-password to log in, poison access logs for LFI RCE, exploit trusted-host rlogin, then escape sudo nano to root the box
lfilog-poisoningrloginhosts.equivsudo
AD / Kerberos
Guess a weak trainee password, reset a Pre2K computer account, then abuse ADCS ESC1 to obtain the Administrator hash and take over the domain controller
smbrid-cyclingpre2kadcsesc1
AD / Kerberos
Crack an MS Access DB for domain creds, abuse Pre2K GenericWrite for RDP, then exploit ZeroLogon and DCSync to dump all hashes and root the DC
msaccessjohnpre2kgenericwritezerologon
AD / Kerberos
Spray for accounts pending password change, chain GenericAll and ReadGMSAPassword via BloodHound, then abuse ADCS ESC4 to impersonate Administrator
bloodhoundgenericallgmsaadcsesc4
Linux Privesc
Abuse an NFS export to impersonate a user, crack a PostgreSQL hash from psql history, then hijack a root backup cron with SUID bash to root the box
nfspostgresqlssh-socketbash_historysuid
AD / Kerberos
Spray to enter Lansweeper, capture scan creds with an SSH honeypot, abuse GenericAll for a foothold, then deploy or decrypt Lansweeper creds to reach SYSTEM
lansweepersshesamebloodhoundgenericallpassword-spray
Windows Privesc
Break out of a passwordless RDP kiosk via a second Edge instance, unmask a Remote Desktop Plus admin password, then bypass UAC to root the box
kiosk-escaperdpmsedgeremote-desktop-plusuac
HackSmarter.org
HackSmarter.org
HACKSMARTER · 12
AD / Kerberos
Chain a Jenkins foothold and sudo binary abuse on Ubuntu into Kerberos keytab theft and ADCS ESC1 to seize Domain Admin
jenkinssudokeytabadcsesc1
AD / Kerberos
Chain Kerberoasting, shadow credential attacks, and ADCS ESC1 across service accounts to escalate a standard user to Domain Admin
kerberoastingshadow-credsadcsesc1genericall
Linux DFIR
Leak credentials over SNMP then chain cronjob replacement, Unix socket hijacking, and SUID PATH hijacking to reach root on a Linux server
snmpcronjobunix-socketsocatsuid
AD / Kerberos
Crack leaked MD5 hashes then chain password spraying, Kerberoasting, NTLM theft, and SeBackupPrivilege to compromise the AD domain
kerberoastingpassword-sprayntlm_theftsebackuppass-the-hash
AD / Kerberos
Abuse a description-field password and ForceChangePassword, then leverage the BadSuccessor dMSA attack to reach Enterprise Admin on Server 2025
badsuccessorforcechangepasswordwinrmdmsas4u2self
AD / Kerberos
Pivot from an RDP jump box through RBCD, DPAPI secrets, and Backup Operators to a DCSync that fully compromises the domain
rbcddpapibackup-operatorsdcsyncrdp
AD / Kerberos
Exploit Jinja2 SSTI on a Linux web server, reuse keys and cracked hashes to pivot across Windows hosts, and abuse GPO to own the domain
sstissh-keybackup-operatorsgpo-abusebloodhound
AD / Kerberos
Steal a hash via NTLM theft, abuse GenericAll, then pivot with ligolo-ng into MSSQL and SeImpersonate to reach SYSTEM
ntlm_theftgenericallligolo-ngmssqlxp_cmdshell
AD / Kerberos
Run a Sliver C2 stager past Defender, loot Edge and autologon credentials, then tunnel to a MySQL server to exfiltrate the flag
sliverc2seimpersonateautologonmysql
AD / Kerberos
Enumerate usernames from a website, AS-REP roast, crack a Cisco router config, then abuse GPO Creator Owners to compromise the domain
asreproastroundcubecisco-configgpo-abusenetexec
Linux DFIR
Abuse Oracle CREATE ANY DIRECTORY via CloudBeaver to read an SSH key, then replace a root-run script to fully compromise the Linux server
oracleplsqlcloudbeaverssh-keysudo
AD / Kerberos
Crack a share document password, spray it, then chain shadow credentials and ADCS ESC1 to escalate to Domain Admin
password-sprayshadow-credsforcechangepasswordadcsesc1
Unlisted Labs
Unlisted Labs
UNLISTED · 11
Digital Forensics
Solve ten CTF challenges across forensics, crypto, reversing, stego, and OSINT using strings, ROT decoding, and packet analysis
exiftoolstringspcapwiresharksteganography
Network Forensics
Work through blue-team CTF challenges spanning packet analysis, DNS tunneling, auditd, Suricata IDS, and Windows event logs
wiresharkpcapdns-tunnelsuricataauditd
Incident Response
Recap the Cyber Range Thailand 2024 final round experience without a technical write-up of the challenges
ctfblue-teamdfirreview
Memory Forensics
Recover an encrypted flag image from a Windows memory dump by extracting the AES key and IV from a PowerShell script and env vars
volatilitymftparserfilescanaespowershell
Malware Analysis
Recover a Windows Defender quarantined malware with dexray to extract the base64-encoded flag from its PowerShell payload
defenderquarantinedexrayremnuxpowershell
Incident Response
Work through incident-response and reverse-engineering challenges chaining web recon, hashes, and a password-protected evidence file
incidentreversingransomwaresha256web
Log Analysis
Trace an attacker through Windows Security event logs via process-creation 4688 events, rundll32 payloads, and AES-decrypted clues
event-4688security-logrundll32aeshta
Windows DFIR
Investigate malicious PDFs, stealers and ransomware using exiftool metadata, VirusTotal behavior, and email analysis
exiftoolpdfvirustotalmalwareransomware
Network Forensics
Analyze PCAPs to recover LSB-hidden flags, brute FTP logins, and decrypt C2 traffic alongside mobile forensics tasks
wiresharkpcaplsb-stegoftpmobile
Reverse Engineering
Reverse ELF binaries in Ghidra to brute-force seeds and generate flags, plus crypto and programming challenge solutions
ghidraelfbruteforcecryptoprogramming
Reverse Engineering
Solve mixed crypto, forensics, web and OSINT challenges including Vigenere, low-exponent RSA cube root, and EXIF GPS extraction
vigenerersaexiftoolgpsosint
Unlisted Labs
Unlisted Labs → MemLabs
UNLISTED · 6
LetsDefend
LetsDefend → LetsDefend Alert
LETSDEFEND · 4
Unlisted Labs
Unlisted Labs → Level Effect Cyber Defense CTF
UNLISTED · 3
no write-ups matched your query ·