Trusted By Default (TryHackMe)
Link to the challenge on TryHackMe: Trusted By Default Introduction Trusted By Default is a Splunk-based investigation room on TryHackMe that drops you into a live-fire correlation exercise across web

Search for a command to run...
Articles tagged with #splunk
Link to the challenge on TryHackMe: Trusted By Default Introduction Trusted By Default is a Splunk-based investigation room on TryHackMe that drops you into a live-fire correlation exercise across web

Link to Investigating with Splunk challenge on TryHackme SOC Analyst Johny has observed some anomalous behaviours in the logs of a few windows machines. It looks like the adversary has access to some

Link to the challenge/walkthrough on TryHackMe: Traffic Analysis Pitfalls Introduction It is 02:47. Our SIEM fires an alert. Alert: Large Outbound Transfer Source: 10.10.15.44 (WKST-FINANCE-04) D

Introduction Email is a critical communication channel in any organisation, which makes it a prime target for attackers. Once a mailbox is compromised, attackers can read emails, exfiltrate sensitive

Introduction SharePoint Online is one of the most targeted M365 services, as it often stores sensitive files and can be used to propagate the attack. This room will explore the most common attack scen

Introduction In an AD environment, attackers who compromise a single account rarely stop there. They use built-in protocols like SMB and RDP to move from the initial foothold to servers that hold what
