
SOC335-CVE-2024-49138-Exploitation-Detected
LetsDefend SOC lab investigating CVE-2024-49138 and related malicious activity.

LetsDefend SOC lab investigating CVE-2024-49138 and related malicious activity.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

All-in-One malware analysis tool.

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

DFIR investigation + 7 Suricata rules on a simulated NexaCorp intrusion (vsftpd 2.3.4 CVE-2011-2523 + MITRE Caldera C2). 4-day solo engagement…

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

A Zeek Wireguard protocol analyzer based on Spicy.

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

A Zeek OSPF packet analyzer based on Spicy.

Powershell module for VMWare vSphere forensics