Skip to main content

2 posts tagged with "DFIR"

Content related to Digital Forensics and Incident Response, including analysis, investigation, and recovery.

View All Tags

HTB Sherlock: Brutus

· 7 min read
Cielo Shee
Senior Information Officer/Engineer

Hack The Box is an online cybersecurity training platform that allows individuals to test and advance their skills in penetration testing, digital forensics, and incident response. The "Sherlocks" are a series of defensive challenges focused on digital forensics and incident response (DFIR).

This post covers the "Brutus" Sherlock - investigating a brute-force attack against a Confluence server's SSH service. I'll walk through analyzing logs to trace the attacker's path from initial access to privilege escalation and persistence.

HTB Sherlock: Unit42

· 5 min read
Cielo Shee
Senior Information Officer/Engineer

This post covers the Unit42 Sherlock, a challenge inspired by a real-world UltraVNC campaign researched by Palo Alto's Unit42 team.

In this investigation, I'll be diving into Sysmon logs and analyzing various Event IDs to trace malicious activities on a compromised Windows system.