Tag: #htb
8 posts
HTB Sherlock: CrownJewel-1
VSS, an NTDS.dit copy, and four artifacts to piece it together. My quick notes from CrownJewel-1.
HTB Sherlock: OpTinselTrace-3
A suspicious Christmas gift, Volatility, and PowerShell logs. The bits I kept from OpTinselTrace-3.
HTB Sherlocks: Notes from the Blue Team Grind
Quick notes from 12 Sherlocks: useful artifacts, little gotchas, and things to remember for the next lab.
HTB Sherlock: MisCloud
GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.
HTB Sherlock: Nubilum-1
AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.
HTB Sherlock: Subatomic
Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.
My 10-Week HTB Sherlocks Blue Team Roadmap
A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.
Windows Forensics & Event Log Analysis (HTB Sherlock: GhostTrace)
Windows forensics and event log analysis report converted from PDF to MDX.