
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
This repository contains my full investigation and technical write‑up of a Conti ransomware compromise targeting a Microsoft Exchange server.
The analysis was conducted using Splunk 8.2.2, reviewing 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain.
Conti Ransomware Write Up.pdf >>> Full 24‑page technical reportThis project showcases my ability to:
For collaboration or discussion, connect with me on LinkedIn.