Posts on blue-team
10 posts on blue-team. Notes from public sources and my own test lab.
Think Twice Before Opening That File: A Peek into the Kitchen of Malware Analysis
My journey from a 'zombie' computer to a Red Team Lead taught me one thing: malware analysis is as much about discipline as it is about art. Here's how we dissect those suspicious files safely.
Seeing Behind the Mask: A Late-Night Shift in the Analysis Lab
Signature-based detection is no longer enough. Let's dive into the 'kitchen' of malware analysis to see how we unmask modern, fileless threats using static and dynamic techniques.
Drowning in the Sandbox: The 'Automated Analysis' Myth vs. Reality in Malware Analysis
If you're blindly trusting VirusTotal or automated sandboxes for critical systems, you're not just being lazy—you're potentially tipping off the attackers. Let's dive into why we need to get our hands dirty with manual analysis and proper OPSEC.
The Labyrinth Inside the Code: Pulling an All-Nighter for Binary Analysis
It's 3 AM, your screen is glowing blue, and a suspicious notepad.exe is trying to exfiltrate data. Let's dive into the anatomy of a fileless malware attack and see how we can harden our defenses.
It’s Not Just the Code Sweating on the Analysis Table: First Steps into the Malware World
Malware analysis is like an autopsy on a patient that is still very much alive and trying to kill you. Here is how we start tearing into the black box.
A Tale of 'Update.exe': Dissecting Malware in a Lab Environment
Ever wondered if that suspicious binary on your desk is just logging or exfiltrating your entire database? Let's dive into the 'kitchen' work of security and learn how to safely analyze malware.
Stop Playing in the Sandbox: Facing the Realities of Malware Analysis
Relying solely on automated sandboxes is a trap. Let's dive into the real-world mindset of malware analysis, covering entropy, static inspection, and why your automated tools might be lying to you.
Think That File Is Gone? The Silent Scream of Digital Traces
A deep dive into the world of digital forensics, why you shouldn't just pull the plug on a compromised system, and how to catch an attacker's 'whispers' using Volatility.
That 3 AM Phone Call: The Side of Incident Response You Won't Find in Textbooks
Incident response isn't just about technical steps; it's about managing chaos. Here's what really happens when the SOC calls you at midnight.
Hunting the Silence: Are You Just Waiting or Actually Looking?
Everything looks green on your dashboard, but is it really? Learn why waiting for alarms is a trap and how to start hunting threats instead.