WelcomešŸ–


Here I share my thoughts on InfoSec news, plus technical guides and writeups.
  • Splunk

    Threat hunting on SIEM (Splunk)

    By Ren Sie
    Refer to Splunk for the challenge room on TryHackMe Scenario SOC Analyst Johny noticed unusual activity in the logs from several Windows machines. It seems that an attacker has gained access to these machines and set up backdoors. Johny's manager has asked him to collect the logs from these suspected... [Read More]
  • Sysmon - Retracted

    Sysmon logs Investigation

    By Ren Sie
    Refer to Retracted for the challenge room on TryHackMe A Mother's Plea "Thanks for coming. I know you are busy with your new job, but I did not know who else to turn to.""So I downloaded and ran an installer for an antivirus program I needed. After a while, I... [Read More]
  • Wazuh - Monday Monitor

    Discovered persistent threat on compromised endpoint with EDR (Wazuh)

    By Ren Sie
    Refer to Mondaymonitor for the challenge room on TryHackMe Scenario Swiftspend Finance, the coolest fintech company around, is enhancing its cybersecurity to protect against digital threats and keep customers safe. Led by the tech-savvy Senior Security Engineer John Sterling, Swiftspend is focusing on improving endpoint monitoring with Wazuh and Sysmon.... [Read More]
  • Linux forensics - Disgruntled

    Linux logs and suspicious binary exmination

    By Ren Sie
    Refer to Disgruntled for the challenge room on TryHackMe Task An IT employee from CyberT has been arrested for running a phishing operation. CyberT has requested our assistance to determine if this individual compromised any of their assets. Nothing suspicious... So far Here’s the machine that our dissatisfied IT user... [Read More]