Recent Articles

njRAT.exe Report

njRAT.exe Report

Malware sample source:https://github.com/ytisf/theZoo/tree/master/malware/Binaries/njRAT-v0.6.4Analysis EnvironmentFlare VM, Remnux Overview: The binary njRAT.exe is a Remote Access Trojan (RAT) that ...

Security Investigation with Splunk

Security Investigation with Splunk

In this exercise, I investigated failed authentication attempts with Splunk to detect potential threat actors attempting to gain access to the environment. This exercise is divided into three parts: D...

Understanding Threat Hunting

Understanding Threat Hunting

A proactive approach to threat detection Understanding Threat Hunting Organisations use Security Information and Event Management (SIEM) software which comprises security monitoring and log management...

Network Traffic Analysis with Security Onion

Network Traffic Analysis with Security Onion

In this exercise, I investigate an incident wherein a user got compromised through a malicious email. My goal is to figure out how the computer got infected and document my findings.This malware exerc...