// the archive · where it began
A Cyber Journey
The decayed chapter, kept whole. Where I learned to think like a defender and a breaker, before the building began.
TryHackMe walkthroughs, DFIR write-ups, blue-team notes, the occasional red-team detour. Messy, curious, and completely worth it. This is a finished story rather than the headline, the foundation everything since was built on.
If you followed along back then, welcome back. If you are just arriving, pull up a chair and browse.
2025
50 postsBoogeyman 3:WALKTHROUGH
Due to the previous attacks of Boogeyman, Quick Logistics LLC hired a managed security service provider to handle its Security Operations Center. Little did they know, the Boogeyman was still…
Boogeyman 2:WALKTHROUGH
After having a severe attack from the Boogeyman, Quick Logistics LLC improved its security defences. However, the Boogeyman returns with new and improved tactics, techniques and procedures. In this…
Boogeyman 1: WALKTHROUGH
Uncover the secrets of the new emerging threat, the Boogeyman. In this room, you will be tasked to analyse the Tactics, Techniques, and Procedures (TTPs) executed by a threat group, from obtaining…
Tempest: WALKTHROUGH
This room aims to introduce the process of analysing endpoint and network logs from a compromised asset. Given the artefacts, we will aim to uncover the incident from the Tempest machine. In this…
Phishing Prevention: WALKTHROUGH
There are various actions a defender can take to help protect the users from falling victim to a malicious email. Some examples of these actions are listed below: Email Security (SPF, DKIM, DMARC)…
Phishing Analysis Tools: WALKTHROUGH
Remember from Phishing Room 1; we covered how to manually sift through the email raw source code to extract information. In this room, we will look at various tools that will aid us in analyzing…
Phishing Emails in Action
As this room’s answers are all in the readings there won’t be any screenshots in this writeup. just look closely! Now that we covered the basics concerning emails in Phishing Emails 1, let's dive…
Phishing Analysis Fundamentals
Spam and Phishing are common social engineering attacks. In social engineering, phishing attack vectors can be a phone call, a text message, or an email. As you should have already guessed, our…
Secret Recipe: WALKTHROUGH
Storyline Jasmine owns a famous New York coffee shop Coffely which is famous city-wide for its unique taste. Only Jasmine keeps the original copy of the recipe, and she only keeps it on her work…
Critical: WALKTHROUGH
Incident Scenario Our user "Hattori" has reported strange behavior on his computer and realized that some PDF files have been encrypted, including a critical document to the company named…
Velociraptor: WALKTHROUGH
Velociraptor In this room, we will explore Rapid7's newly acquired tool known as Velociraptor. Per the official Velociraptor documentation, "Velociraptor is a unique, advanced open-source endpoint…
Disgruntled: WALKTHROUGH
Hey, kid! Good, you’re here! Not sure if you’ve seen the news, but an employee from the IT department of one of our clients (CyberT) got arrested by the police. The guy was running a successful…
Unattended: WALKTHROUGH
Welcome to the team, kid. I have something for you to get your feet wet. Our client has a newly hired employee who saw a suspicious-looking janitor exiting his office as he was about to return from…
Intro to Malware Analysis
Every once in a while, when you are working as a SOC analyst, you will come across content (a file or traffic) that seems suspicious, and you will have to decide whether that content is malicious or…
TheHive Project
Welcome to TheHive Project Outline! This room will cover the foundations of using the TheHive Project, a Security Incident Response Platform. Specifically, we will be looking at: What TheHive is? An…
Kape: WALKTHROUGH
Revisiting Windows Forensics In the Windows Forensics 1 and Windows Forensics 2 rooms, we learned about the different artifacts which store information about a user's activity on a system. We also…
Windows Forensics 2:WALKTHROUGH
Introduction We learned about Windows Forensics in the previous room and practiced extracting forensic artifacts from the Windows Registry. We learned about gathering system information, user…
Windows Forensics 1: WALKTHROUGH
Introduction to Computer Forensics for Windows: Computer forensics is an essential field of cyber security that involves gathering evidence of activities performed on computers. It is a part of the…
DFIR An Introduction: WALKTHROUGH
Learning Objectives Security breaches and incidents happen despite the security teams trying their best to avoid them worldwide. The prudent approach in such a scenario is to prepare for the time…
Benign: WALKTHROUGH
We will investigate host-centric logs in this challenge room to find suspicious process execution. To learn more about Splunk and how to investigate the logs, look at the rooms splunk101 and…
Investigating With Splunk: WALKTHROUGH
SOC Analyst Johny has observed some anomalous behaviours in the logs of a few windows machines. It looks like the adversary has access to some of these machines and successfully created some…
BlackBox UploadVuln
We'll look at this as a step-by-step process. Let's say that we've been given a website to perform a security audit on. The first thing we would do is take a look at the website as a whole. Using…
Splunk Incident Handling: WALKTHROUGH
This room covers an incident Handling scenario using Splunk. An incident from a security perspective is "Any event or action, that has a negative consequence on the security of a user/computer or an…
Splunk:Basics: WALKTHROUGH
Splunk is one of the leading SIEM solutions in the market that provides the ability to collect, analyze and correlate the network and machine logs in real-time. In this room, we will explore the…
ItsyBitsy (ELK): WALKTHROUGH
In this challenge room, we will take a simple challenge to investigate an alert by IDS regarding a potential C2 communication. Room Machine Before moving forward, deploy the machine. When you deploy…
ELK 101: WALKTHROUGH
In this room, we will learn how to utilize the Kibana interface to search, filter, and create visualizations and dashboards, while investigating VPN logs for anomalies. This room also covers a brief…
Challenge:Monday Monitor: WALKTHROUGH
Scenario Swiftspend Finance, the coolest fintech company in town, is on a mission to level up its cyber security game to keep those digital adversaries at bay and ensure their customers stay safe…
Access Lists:LAB
Welcome to the Applying Security Protocols Practice Lab. In this module, you will be provided with the instructions and devices needed to develop your hands-on skills. In this module, you will…
Practical Help Desk
Just completed the Practical Help Desk course from TCM Security. This course is 🚨 FREE 🚨 which is amazing as it does an excellent job at covering essential skills needed for the job market. Andrew…
Dell Inspirion 15 3515
I recently purchased a refurbished Dell Inspirion 15 3515 AMD Ryzen 5 3450u 2.1Ghz for an amazingly low price. As with all things that are too good to be true I expected to run into some issues with…
Layer 2 Security:LAB
DHCP Snooping, Dynamic ARP inspection, Port Security Exercise 4 - Configuring Layer 2 Security Features Sometimes a network could have traffic that is malicious. These types of traffic cannot be…
SIEM: NOTES
What is SIEM SIEM stands for Security Information and Event Management system. It is a tool that collects data from various endpoints/network devices across the network, stores them at a centralized…
Wazuh: WALKTHROUGH
Created in 2015, Wazuh is an open-source, freely available and extensive EDR solution. It can be used in all scales of environments. Wazuh operates on a management and agent module. Simply, a device…
Endpoint Security: NOTES
Wazuh Wazuh is an open-source, freely available, and extensive EDR solution, which Security Engineers can deploy in all scales of environments. Wazuh operates on a management and agent model where a…
TShark: NOTES
TShark is an open-source command-line network traffic analyser. It is created by the Wireshark developers and has most of the features of Wireshark. It is commonly used as a command-line version of…
Wireshark (Defensive)
Capture Filter Syntax These filters use byte offsets hex values and masks with boolean operators, and it is not easy to understand/predict the filter's purpose at first glance. The base syntax is…
Brim: NOTES
Brim vs Wireshark vs Zeek While each of them is powerful and useful, it is good to know the strengths and weaknesses of each tool and which one to use for the best outcome. As a traffic capture…
Ubuntu Zeek: NOTES
CategoryCommand Purpose and UsageCategoryCommand Purpose and UsageBasicsView the command history:ubuntu@ubuntu$ history Execute the 10th command in history: ubuntu@ubuntu$ !10 Execute the previous…
OpenCTI: NOTES
What is OpenCTI and how is it used? How would I navigate through the platform? What functionalities will be important during a security threat analysis? Cyber Threat Intelligence is typically a…
OSINT Tools: NOTES
Using UrlScan.io to scan for malicious URLs. Using Abuse.ch to track malware and botnet indicators. Investigate phishing emails using PhishTool Using Cisco's Talos Intelligence platform for intel…
CTI: NOTES
Cyber Threat Intelligence (CTI) can be defined as evidence-based knowledge about adversaries, including their indicators, tactics, motivations, and actionable advice against them. These can be…
UKC: NOTES
Threat modelling, in a cybersecurity context, is a series of steps to ultimately improve the security of a system. Threat modelling is about identifying risk and essentially boils down to…
Authentication Attacks:NOTES
Types: MFA Fatigue Attacks - Social Engineering Cyber attack repeatedly sending MFA requests; SPAM attack; Pass-The-Hash Attack - Steal Hashed user credentials then use them to create a new session…
ReconTools:NOTES
Wayback Machine For reviewing internet archives; Free Via internet browser; archive.org/web ; Can see historical data about a website to identify new changes which may have vulnerabilities; Can…
Exploit Tools:NOTES
Metasploit Identifies potential exploits and provides ability to execute; Netcat Creates communication channels between two systems; Installed on linux, Install Nmap on windows to access ncat…
AuthTools:NOTES
CrackMapExec Dump Hashes in for cracking and move laterally in network; Various Protocols - rdp, winrm, ldap, ssh, mssql, smb, ftp; --shares Enumerate shares to show accounts that are vulnerable...
THM Web App Resources
OWASP Favicon Database: Other places to find information only using basic tools: robots.txt, sitemap.xml, HTTP Headers, Framework Stack - developer tools Google Hacking / Dorking Google hacking /…
MISP: NOTES
MISP - MALWARE INFORMATION SHARING PLATFORM MISP (Malware Information Sharing Platform) is an open-source threat information platform that facilitates the collection, storage and distribution of…
Cyber Kill Chain: NOTES
Reconnaissance is discovering and collecting information on the system and the victim. The reconnaissance phase is the planning phase for the adversaries. OSINT (Open-Source Intelligence) also falls…
Vulnerability Tools:NOTES
Nikto Open source tool used to scan web servers; Vulnerability scans for known issues; Checks for configuration errors; TruffleHog Scans for exposed secrets such as API Keys, Passwords and Token…
