
SOC335-CVE-2024-49138-Exploitation-Detected
LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.

LetsDefend SOC lab investigating CVE-2024-49138 exploitation and related malicious activity.

Powershell module for VMWare vSphere forensics

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

Selective protocol extractor from PCAPs or interfaces

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…