SOC & Incident Response
Security Operations & IR Case Studies
Real-world incident investigations covering the full IR lifecycle — from initial detection and analysis through containment, eradication, and lessons learned.
Cobalt Strike — Suspicious PowerShell Investigation
Full incident investigation of a Cobalt Strike beacon delivered via encoded PowerShell script. Initial access through RDP brute force, followed by privilege escalation, internal port scanning, lateral movement, and database exfiltration via netcat.
WSHRAT — VBScript Malware Incident Response
End-to-end incident response for a WSHRAT malware infection. Initial compromise via spear-phishing email impersonating GoDaddy, double-extension VBS masquerading as an XLS file, Registry Run key persistence, and C2 beaconing to remote infrastructure.