Investigating. Learning. Sharing.
Blog
Technical notes, security investigations and lessons learned. A place to document what I discover and make the reasoning useful to others.
Articles
Under the hood of Windows: Using Process Monitor
A step-by-step look at svchost.exe with Process Monitor: filtering events, following file and registry activity, and understanding the parent process.
Packet capture analysis of a SocGholish and AsyncRAT infection
Following a SocGholish and AsyncRAT infection through a packet capture: suspicious TLS traffic, DNS correlations, HTTP streams and obfuscated PowerShell.
Investigating Koi Stealer malware using Wireshark
An end-to-end Wireshark investigation of a Koi Stealer packet capture, examining beaconing, HTTP payloads, internal network activity and indicators of compromise.
No articles match these filters. Try another search or clear the filters.