
Hands-on SOC investigation of CVE-2024-49138 using LetsDefend, VirusTotal, Hybrid Analysis, TrueFort, and ChatGPT.
Hands-on SOC investigation and incident response simulation using LetsDefend, focused on a real-world exploitation of CVE-2024-49138 — a privilege escalation vulnerability in Windows CLFS driver.
svohost.exepowershell.exe\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9https://files-ld.s3.us-east-2.amazonaws.com/service-installer.zip185.107.56.141svohost.exe) used for privilege escalation.Successfully triaged, investigated, and documented the attack chain leveraging CVE-2024-49138. This lab helped reinforce my skills in incident response, behavioral analysis, and threat detection.







“Getting 1% better every day.”