PinnedInDetect FYIbyAlex John·Dec 2, 2024Adrift in the Cloud: A Forensic Dive into Container DriftIn this discussion, I’ll be diving into container drift detection, specifically, analyzing container drift from a forensics perspective
PinnedInDetect FYIbyAlex John·May 2, 2023Detecting and responding to ESXi compromise with SplunkA lack of AV/EDR on platforms such as these shouldn’t limit a defender’s ability to detect & respond to threats on virtualization…A response icon1A response icon1
PinnedAlex John·Mar 12, 2023How I managed to get 92% on the GIAC GREM CyberLive exam!“It may seem difficult at first, but everything is difficult at first.” — Miyamoto MusashiA response icon2A response icon2
InDetect FYIbyAlex John·Apr 1, 2022Detecting and Responding to Spring4Shell with SplunkIt’s that time of the week again when you are just about ready to sit back with a nice glass of Longmorn 16 & long no more. But then, some…
Alex John·Feb 26, 2022HermeticWiper — Hermetica Digital Ltd. your friendly neighbourhood wipe r part 1TL;DR: Blue teamers can detect this by looking for sysmon new file creation event for a file ending with .sys in System32. You can also…
Alex John·Feb 6, 2022Automating Intelligence-Driven Threat Hunting without a SOARI’ve always been a proponent of XREFing organizational context with cyber threat intelligence to produce actionable insights, i.e…
Alex John·Oct 23, 2020How to prepare for the eCIR examSo, if you are here, you are either planning to purchase the IHRP course or just about ready to attempt the exam. Before my exam, I had…A response icon1A response icon1