AS-REP Roasting
Overview AS-REP Roasting is an Active Directory attack that targets user accounts configured with “Do not require Kerberos preauthentication.” Unlike […]
Overview AS-REP Roasting is an Active Directory attack that targets user accounts configured with “Do not require Kerberos preauthentication.” Unlike […]
Overview In this Hack the Box investigation, I analyzed over 500,000 events across multiple log sources to identify malicious activity
Intrusion Detection with Splunk: Uncovering a Full Domain Compromise Read Post »
Overview This was one of those issues that feels like it could go a hundred different directions at first. My
Incident-Style Troubleshooting: Resolving a Critical Windows System Failure Read Post »
Overview After deploying an internet-facing Cowrie honeypot and integrating it with Elastic SIEM, I began collecting attack data almost immediately.
Analyzing Real SSH Attack Traffic with Cowrie and Elastic Read Post »
Overview This was a project that had been sitting on my “to do list” for several months. I had come
Creating an Internet-Exposed Cowrie Honeypot Read Post »
Overview Over the past several months, I’ve been intentionally spending time working through hands-on detection and investigation exercises to sharpen
Building Valuable SOC Skills Through Hands-On Detection Work Read Post »
Overview I’ve been blessed to be extremely busy the first few months of this new year, both professionally and personally.
Building Practical SIEM Dashboards in Elastic Read Post »
Overview To stay current with detection and response skills, I’ve started working through the Hack the Box SOC Analyst Pathway.
Incident Handling: From Preparation to Detection & Analysis Read Post »
Expanding the Investigation In Part One, the focus was on quickly identifying attacker tooling and vulnerable endpoints using a lightweight
TryHackMe – Juicy Details Challenge: Log Analysis with Python – Part Two Read Post »
Investigation Approach This TryHackMe challenge was a great opportunity to practice log analysis while also reinforcing what I’ve been learning
TryHackMe – Juicy Details Challenge: Log Analysis with Python – Part One Read Post »