
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
Ce dépôt contient mon enquête complète et mon analyse technique d'une compromission par le ransomware Conti ciblant un serveur Microsoft Exchange.
L'analyse a été réalisée avec Splunk 8.2.2, en examinant 28 145 événements provenant des sources de journaux Windows Security, Sysmon et IIS pour reconstituer la chaîne d'attaque complète.
Conti Ransomware Write Up.pdf >>> Rapport technique complet de 24 pagesCe projet démontre ma capacité à :
Pour toute collaboration ou discussion, connectez-vous avec moi sur LinkedIn.