
Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows Security, Sysmon, and IIS log sources to reconstruct the complete attack chain. Identified three exploited CVEs (CVE-2020-0796, CVE-2018-13374, CVE-2018-13379), located a trojanised cmd.exe
이 저장소는 Microsoft Exchange 서버를 대상으로 한 Conti 랜섬웨어 침해에 대한 전체 조사 및 기술 분석 보고서를 포함합니다.
분석은 Splunk 8.2.2를 사용하여 수행되었으며, Windows 보안, Sysmon 및 IIS 로그 소스에서 28,145개 이벤트를 검토하여 전체 공격 체인을 재구성했습니다.
Conti Ransomware Write Up.pdf >>> 전체 24페이지 기술 보고서이 프로젝트는 제 능력을 보여줍니다:
협업이나 논의를 원하시면 LinkedIn에서 저와 연결하세요.