Open in app

Sign In

Write

Sign In

Leylaliyeva
Leylaliyeva

23 Followers

Home

About

Pinned

Boss Of The SOC v1 Writeup

https://cyberdefenders.org/blueteam-ctf-challenges/15 Today I will assist you to solve the Boss of the SOC v1 challenge in the easiest way from the Splunk team hosted at Cyberdefenders.org. Let’s go. Questions and Solutions 1. This is a simple question to get you familiar with submitting answers. What is the name of the company that makes…

11 min read

Boss Of The SOC v1 Writeup
Boss Of The SOC v1 Writeup

11 min read


Pinned

“ SOC166 — Javascript Code Detected in Requested URL” investigation

Hello, today I will write about investigation of “SOC166 — Javascript Code Detected in Requested URL” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step of the playbook is asking us to understand…

5 min read

“ SOC166 — Javascript Code Detected in Requested URL” investigation
“ SOC166 — Javascript Code Detected in Requested URL” investigation

5 min read


Pinned

“ SOC141 — Phishing URL Detected ” investigation

Hello, today I will write about investigation of “SOC141 — Phishing URL Detected” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step is to ‘Parse Email’ and gather information about the incoming email…

4 min read

“ SOC141 — Phishing URL Detected ” investigation
“ SOC141 — Phishing URL Detected ” investigation

4 min read


Pinned

“ SOC140 — Phishing Mail Detected — Suspicious Task Scheduler “ investigation

Hello, today I will write about investigation of “SOC140 — Phishing Mail Detected — Suspicious Task Scheduler” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step is to ‘Parse Email’ and gather information about the incoming email. The alert itself contains the majority of the information: § The alarm was triggered as medium…

4 min read

“ SOC140 — Phishing Mail Detected — Suspicious Task Scheduler “ investigation
“ SOC140 — Phishing Mail Detected — Suspicious Task Scheduler “ investigation

4 min read


Pinned

“ SOC114 — Malicious Attachment Detected — Phishing Alert ” investigation

Hello, today I will write about investigation of “SOC114 — Malicious Attachment Detected — Phishing Alert” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step is to ‘Parse Email’ and gather information about…

6 min read

“ SOC114 — Malicious Attachment Detected — Phishing Alert ” investigation
“ SOC114 — Malicious Attachment Detected — Phishing Alert ” investigation

6 min read


Nov 28, 2022

“ SOC170 — Passwd Found in Requested URL — Possible LFI Attack” investigation

Hello, today I will write about investigation of “SOC170 — Passwd Found in Requested URL — Possible LFI Attack” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. We may conclude from the specifics that the…

2 min read

“ SOC170 — Passwd Found in Requested URL — Possible LFI Attack” investigation
“ SOC170 — Passwd Found in Requested URL — Possible LFI Attack” investigation

2 min read


Nov 28, 2022

“ SOC168 — Whoami Command Detected in Request Body” investigation

Hello, today I will write about investigation of “SOC168 — Whoami Command Detected in Request Body” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step of the playbook is asking us to understand…

5 min read

“ SOC168 — Whoami Command Detected in Request Body” investigation
“ SOC168 — Whoami Command Detected in Request Body” investigation

5 min read


Nov 28, 2022

“ SOC167 — LS Command Detected in Requested URL” investigation

Hello, today I will write about investigation of “SOC167 — LS Command Detected in Requested URL” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step of the playbook is asking us to understand…

4 min read

“ SOC167 — LS Command Detected in Requested URL” investigation
“ SOC167 — LS Command Detected in Requested URL” investigation

4 min read


Nov 28, 2022

“ SOC169 — Possible IDOR Attack Detected” investigation

Hello, today I will write about investigation of “SOC169 — Possible IDOR Attack Detected” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step of the playbook is asking us to understand why the…

4 min read

“ SOC169 — Possible IDOR Attack Detected” investigation
“ SOC169 — Possible IDOR Attack Detected” investigation

4 min read


Nov 28, 2022

“ SOC165 — Possible SQL Injection Payload Detected” investigation

Hello, today I will write about investigation of “SOC165 — Possible SQL Injection Payload Detected” alarm from letdefend.io. The alert is appears in our investigation channel. After that, we proceed to build the case. Let’s start the playbook. The first step of the playbook is asking us to understand why…

4 min read

“ SOC165 — Possible SQL Injection Payload Detected” investigation
“ SOC165 — Possible SQL Injection Payload Detected” investigation

4 min read

Leylaliyeva

Leylaliyeva

23 Followers

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech