Skip to content

khairulazam.net

Just my simple blog.

khairulazam.net

Just my simple blog.

  • Home
  • About Me
  • Hall of Shame
Analysis Write-Ups

Hunting for Log4j RCE (CVE-2021-44228) using RSA Netwitness

zam 21/12/2021 No Comments

So, if you read my previous article; Hunting for Log4j RCE (CVE-2021-44228) using Splunk & Excel, last time we leveraging Splunk as our platform to hunt event/logs related to this…

Analysis Write-Ups

Hunting for Log4j RCE (CVE-2021-44228) using Splunk & Excel

zam 15/12/2021 1 Comment

As you are aware, there are new Log4j vuln (CVE-2021-44228) vuln been disclosed and exploited in the wild currently. So, I’m using Splunk query as below; based from Splunk blog…

Analysis Write-Ups

Carbon Black query searching for malicious NPM library – coa & rc

zam 08/11/2021 No Comments

Based on GitHub Advisory Database:https://github.com/advisories/GHSA-g2q5-5433-rhrf – Embedded malware in rchttps://github.com/advisories/GHSA-73qr-pfmq-6rp8 – Embedded malware in coa rc affected versions:= 1.2.9= 1.3.9= 2.3.9 coa affected versions:= 2.0.3= 2.0.4= 2.1.1= 2.1.3= 3.0.1= 3.1.3…

Analysis Write-Ups

Break-In Analyzer – Quickly analyze auth.log, secure, utmp & wtmp logs for possible SSH break-in attempts

zam 18/10/2021 No Comments

Recently, I encountered incident where several hosts been infected by < █████████ >. So, to investigate this incident, we received bunch of logs to be analyze; mostly Linux related logs.…

Cybersecurity

Protected: HackTheBox.eu – Illumination (Forensics 20 points)

zam 07/10/2021 No Comments

There is no excerpt because this is a protected post.

Cybersecurity

Protected: HackTheBox.eu – oBfsC4t10n (Forensics 60 points)

zam 07/10/2021 No Comments

There is no excerpt because this is a protected post.

Cybersecurity

Protected: HackTheBox.eu – oBfsC4t10n2 (Forensics 70 points)

zam 06/10/2021 No Comments

There is no excerpt because this is a protected post.

Cybersecurity

Protected: HackTheBox.eu – USB Ripper (Forensics 20 points)

zam 05/10/2021 No Comments

There is no excerpt because this is a protected post.

Analysis Write-Ups

Carbon Black query for Microsoft MSHTML Remote Code Execution Vulnerability (CVE-2021-40444)

zam 09/09/2021 No Comments

Carbon Black query that can be use to detect if any MSHTML RCE happened (probably need to be refined more): Search if any assets making connections towards IOCs (known IOCs…

Analysis Write-Ups

Extracting password from data leaks dump files

zam 28/04/2021 1 Comment

Recently I’ve read about this data leak; COMB: largest breach of all time leaked online with 3.2 billion records. According to the article, it was known as “Compilation of Many…

Posts pagination

1 2 3 … 13

Ads

Recent Posts

  • From ClickFix/ClickVerify to Lumma Stealer – The Rise of Self-Pwn Techniques
  • Malcore.io Challenge – Stacy
  • Deobfuscating Malicious PowerShell Script – ClickFix PowerShell
  • Deobfuscating PHP Webshell
  • Wargames.MY 2023 CTF – Compromised

Recent Comments

  • Marnik on Extracting Quarantine Files from Windows Defender
  • Hunting for Log4j RCE (CVE-2021-44228) using RSA Netwitness | khairulazam.net on Hunting for Log4j RCE (CVE-2021-44228) using Splunk & Excel
  • Rickk on Wifi Pineapple Mark V MR3020 – Bypass verify_pineapple LED pattern
  • Joe the hash cat on Extracting password from data leaks dump files
  • Lakshminarayanan Sethumadhavan on Recover bricked TL-MR3020 via serial console

Archives

Tags

analysis apache apple bash bsd coding configure ctf cygwin debian firewall forensic hack hackthebox honeypot hunting ios linux logfile macos malware metasploit microsoft mongo mybb mysql network&hacking nginx opensource openvz openwrt pcap perl pineapple powershell pwn python ssh tplink ubuntu vmware vps windows wireshark wordpress

Categories

Analysis Write-Ups Cybersecurity Offensive Tutorials

khairulazam.net

Just my simple blog.

Copyright © All rights reserved | Blogus by Themeansar.