Day 66 of Becoming a SOC Analyst — SOC128 Malicious File Upload Attempt (True Positive)
An external attacker targeted the upload functionality on gitServer at 172.16.20.4, successfully uploading phpshell.php (hash 756215a64e7d43153298f1a5a5fde295) via /srcCode/upload.php. HTTP logs confirmed the attacker immediately accessed the shell and executed commands including whoami and cat /etc/passwd — demonstrating full remote code execution on the server. Unlike yesterday's LFI attempt that returned a 404, this one landed clean — file uploaded, shell accessed, commands executed, server compromised. VirusTotal confirmed the hash as malicious and the script as a classic PHP command shell. Walked through the full triage: upload endpoint analysis, web shell content review, HTTP log command execution confirmation, VirusTotal hash enrichment, MITRE mapping (T1190, T1505.003, T1059), and confirming true positive with immediate endpoint isolation.
00:00 Day 66 intro and summary of day 65 ticket
02:00 Alert Details
02:48 Investigation
08:50 Playbook Answers
11:22 5w Log
13:58 Result
SOC128 - Malicious File Upload Attempt
Scenario sourced from LetsDefend.io — one of the best hands-on SOC analyst training platforms out there.
Highly recommend if you're on the same path. I'm documenting every day of my journey to landing a Level 1 SOC Analyst role — the wins, the grinds, and everything in between.
🔵 What I Cover
Threat Detection · Alert Triage · SIEM Analysis · Log Analysis · Incident Response · Blue Team Tools
🚨 Open to Work — Seeking a Level 1 SOC Analyst role in Melbourne or Remote (AU)
📂 Portfolio → inksec.io
💼 LinkedIn → linkedin.com/in/tate-pannam-8b64b23a3
If you chose the red pill... 0x74617465.sh
#socanalyst #blueteam #cybersecurity #webshell #fileupload #PHPShell #rce #incidentresponse #siem #day66 #cybersecurityjourney #Melbourne #letsdefend #letsdefendsoc #threathunting #infosec #blueteamsecurity