CTF Write-ups 33
- Incident Investigation Report: CursorJack — From Malicious MCP to Multi-Region Cryptojacking & Blockchain OSINT
- Incident Investigation Report: ClickFix - VodkaStealer — From Social Engineering to Full Network Compromise
- Threat Intelligence Analysis: IcedID — Tracking a Macro-Enabled Document Delivery Chain
- Incident Investigation Report: AWSRaid — Compromised IAM Credentials & S3 Data Exfiltration
- Memory Forensics Report: RedLine — Extracting Stealer Artifacts from RAM
- Malware Analysis Report: Ramnit — Tracking a Malicious ChromeSetup Downloader
- Incident Response Report: PsExec Hunt — Lateral Movement via SMB & PsExec in a Corporate Network
- Digital Forensics Report: The Crime — Android Mobile Device Forensics of a Homicide Victim
- Incident Response Report: JetBrains TeamCity — Auth Bypass, Web Shell & Credential Tampering
- Incident Response Report: LFI Escalation — From Directory Traversal to Full System Compromise
- Incident Response Report: RediShell — From Jenkins RCE to Container Escape & Kinsing Miner
- Threat Intelligence Analysis: Lespion — OSINT Investigation of an Insider Threat
- Threat Intelligence Analysis: Yellow RAT — Hunting the Jupyter / Yellow Cockatoo Infostealer
- Incident Response Report: PoisonedCredentials — LLMNR/NBT-NS Poisoning & SMB Relay
- Incident Investigation Report: Poisoned PyTorch — Supply-Chain Compromise to Lynx Ransomware
- Incident Investigation Report: XLMRat — Tracing a Multi-Stage AsyncRAT Delivery Chain
- Incident Investigation Report: GrabThePhisher — Dismantling a DeFi Phishing Kit
- Incident Response Report: Maranhão — Trojanized Game Mod to Node.js Infostealer
- Threat Intel Report: RaaS Unfold — RansomHub, The Ransomware Empire Built on Abandoned Affiliates
- Threat Intel Report: Red Stealer (RedLine) — Unmasking a Commodity Credential Harvester via VirusTotal, MalwareBazaar & ThreatFox
- Threat Intel Report: Oski / Stealc Stealer — Analyzing a Credential-Stealing Trojan via ANY.RUN & VirusTotal
- Malware Analysis Report: XWorm RAT — Static & Dynamic Analysis of an Obfuscated .NET Remote Access Trojan
- Incident Response Report: IIS Server Compromise & AgentTesla Infection
- Incident Response Report: Amadey Trojan (APT-C-36) — Memory Forensics & Malware Loader Analysis
- Incident Response Report: XXE Infiltration — XML External Entity Injection, Credential Theft & Web Shell Deployment
- Incident Response Report: Tomcat Takeover — Directory Brute-Force, Credential Cracking & Reverse Shell Persistence
- Incident Response Report: RetailBreach — Stored XSS, Session Hijacking & Path Traversal on ShopSphere
- Incident Response Report: Web Investigation — SQL Injection, Credential Theft & Web Shell Deployment
- Incident Response Report: WebStrike — Server Compromise & Network Forensics Investigation
- Threat Intelligence Analysis: PhishStrike — Email Phishing & Multi-Stage Malware Investigation
- Incident Investigation Report: Operation 'BRabbit' — Bad Rabbit Ransomware Threat Intelligence
- Forensic Investigation Report: Operation 'Hammered' — Linux Log Analysis
- Forensic Investigation Report: Operation 'Reveal' — Memory Analysis