Data Analysis
-
mukul975 Bundle Hunting Credential Stuffing AttacksDetects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins using statistical analysis on Splunk or raw log data.
24.6k -
mukul975 Bundle Hunting For Dns Tunneling With ZeekDetect DNS tunneling and data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, long query lengths, and unusual DNS record types indicating covert channel communication.
24.6k -
mukul975 Bundle Implementing Diamond Model AnalysisProvides a structured framework for analyzing cyber intrusions by examining four core features: Adversary, Capability, Infrastructure, and Victim. Covers implementing the Diamond Model programmatically to classify and correlate intrusion events, build activity threads, and generate pivot-ready intelligence.
Audited 24.6k -
mukul975 Bundle Performing Malware Triage With YaraRapidly classify malware samples against known family signatures using YARA rules, covering rule writing, scanning, and integration with analysis pipelines.
24.6k -
mukul975 Bundle Analyzing Network Packets With ScapyCraft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and traffic anomaly detection in authorized security testing.
24.6k -
mukul975 Bundle Analyzing Network Traffic Of MalwareAnalyzes malware-generated network traffic from PCAP files to identify C2 protocols, data exfiltration, DNS tunneling, and beaconing patterns using Wireshark, Zeek, Suricata, and Python.
24.6k -
mukul975 Bundle Detecting Lateral Movement With ZeekAnalyze Zeek network logs to detect lateral movement techniques including SMB admin share access, DCE/RPC remote service creation, NTLM account spray, Kerberos anomalies, and large internal data transfers.
24.6k -
mukul975 Bundle Extracting Browser History ArtifactsExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
24.6k -
mukul975 Bundle Implementing Alert Fatigue ReductionReduces SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst effectiveness.
24.6k -
mukul975 Bundle Detecting Living Off The Land AttacksDetect abuse of legitimate Windows binaries (LOLBins) used for living off the land attacks by monitoring process creation, command-line arguments, and parent-child relationships.
24.6k -
mukul975 Bundle Analyzing Windows Prefetch With PythonParse Windows Prefetch files using the windowsprefetch Python library to reconstruct application execution history, detect renamed or masquerading binaries, and identify suspicious program execution patterns.
24.6k -
mukul975 Bundle Detecting Attacks On Historian ServersDetect cyber attacks targeting OT historian servers (OSIsoft PI, Ignition, Wonderware) that sit at the IT/OT boundary and serve as pivot points for lateral movement between enterprise and control networks, including data manipulation, unauthorized queries, and exploitation of historian-specific vulnerabilities.
24.6k -
mukul975 Bundle Detecting Beaconing Patterns With ZeekAnalyzes Zeek conn.log connection intervals using statistical methods to detect C2 beaconing patterns, flagging periodic connections with low jitter.
Audited 24.6k -
mukul975 Bundle Detecting Command And Control Over DnsDetects command-and-control (C2) communications tunneled through DNS protocol, including DNS tunneling tools, domain generation algorithms, and encoded payload delivery via TXT/CNAME records.
24.6k -
mukul975 Bundle Detecting Lateral Movement With SplunkDetect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service abuse.
Audited 24.6k -
mukul975 Bundle Recovering Deleted Files With PhotorecRecover deleted files from disk images and storage media using PhotoRec's file signature-based carving engine, regardless of file system damage.
24.6k -
mukul975 Bundle Analyzing Cloud Storage Access PatternsDetect abnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls, and potential data exfiltration using statistical baselines.
24.6k -
mukul975 Bundle Analyzing Ransomware Network IndicatorsAnalyze Zeek conn.log and NetFlow data to detect ransomware network indicators including C2 beaconing, TOR exit node connections, data exfiltration, and suspicious DNS patterns.
Audited 24.6k -
mukul975 Bundle Analyzing Web Server Logs For IntrusionParse Apache and Nginx access logs to detect SQL injection, LFI, XSS, scanner fingerprints, and brute-force patterns using regex-based detection, GeoIP enrichment, and statistical anomaly analysis.
24.6k -
mukul975 Bundle Extracting Windows Event Logs ArtifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
24.6k -
mukul975 Bundle Implementing Network Traffic BaseliningBuild network traffic baselines from NetFlow/IPFIX data using Python pandas for statistical analysis, z-score anomaly detection, and hourly/daily traffic pattern profiling.
Audited 24.6k -
mukul975 Bundle Investigating Insider Threat IndicatorsInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation.
24.6k -
mukul975 Bundle Performing Disk Forensics InvestigationConducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases.
24.6k -
mukul975 Bundle Performing Insider Threat InvestigationInvestigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case.
24.6k -
mukul975 Bundle Analyzing Network Flow Data With NetflowParse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns using the Python netflow library.
24.6k -
mukul975 Bundle Analyzing Network Traffic With WiresharkCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
24.6k -
mukul975 Bundle Analyzing Outlook Pst For Email ForensicsAnalyze Microsoft Outlook PST and OST files for email forensic evidence including message content, headers, attachments, deleted items, and metadata using libpff, pst-utils, and forensic email analysis tools for legal investigations and incident response.
24.6k -
mukul975 Bundle Analyzing Powershell Script Block LoggingParse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques.
24.6k -
mukul975 Bundle Analyzing Windows Lnk Files For ArtifactsParse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
24.6k -
mukul975 Bundle Hunting For Unusual Service InstallationsDetect suspicious Windows service installations (MITRE ATT&CK T1543.003) by parsing System event logs for Event ID 7045, analyzing service binary paths, and identifying indicators of persistence mechanisms.
Audited 24.6k -
mukul975 Bundle Implementing Siem Use Cases For DetectionDesign, implement, test, and maintain SIEM detection rules mapped to MITRE ATT&CK across Splunk, Elastic, and Sentinel platforms.
24.6k -
mukul975 Bundle Analyzing Browser Forensics With HindsightExtract and analyze Chromium-based browser artifacts using Hindsight to reconstruct user web activity for forensic investigations.
24.6k -
mukul975 Bundle Analyzing Lnk File And Jump List ArtifactsAnalyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
24.6k -
mukul975 Bundle Building Incident Timeline With TimesketchBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
24.6k -
mukul975 Bundle Building Role Mining For Rbac OptimizationApply bottom-up and top-down role mining techniques to discover optimal RBAC roles from existing user-permission assignments, reducing role explosion and enforcing least privilege.
24.6k -
mukul975 Bundle Detecting Modbus Command Injection AttacksDetect command injection attacks against Modbus TCP/RTU protocol in ICS environments by monitoring for unauthorized write operations, anomalous function codes, malformed frames, and deviations from established communication baselines.
24.6k