Filtered View

Tag: #dfir

4 posts

Forensics HTB Sherlock

HTB Sherlock: CrownJewel-1

VSS, an NTDS.dit copy, and four artifacts to piece it together. My quick notes from CrownJewel-1.

#htb#sherlocks#blue-team#dfir
2 min read
Forensics HTB Sherlock

HTB Sherlock: OpTinselTrace-3

A suspicious Christmas gift, Volatility, and PowerShell logs. The bits I kept from OpTinselTrace-3.

#htb#sherlocks#blue-team#dfir
medium 2 min read
Forensics HTB Sherlock

HTB Sherlocks: Notes from the Blue Team Grind

Quick notes from 12 Sherlocks: useful artifacts, little gotchas, and things to remember for the next lab.

#htb#sherlocks#blue-team#dfir
4 min read
Research

My 10-Week HTB Sherlocks Blue Team Roadmap

A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.

#htb#sherlocks#blue-team#dfir
15 min read