SOC164 Suspicious Mshta Behavior Walkthrough

Опубликовано: 21 Октябрь 2024
на канале: Cyber Security Free Resource
576
8

Hello and today I will introduce you to another very very nice platform to learn blueteam stuff specifically SOC related stuff named https://letsdefend.io/
This is like a combined SIEM and EDR tool tailored to CTF style like platform. Coll stuff and now I will try to share how to use this platform and the look and feel of the challenges in the form of incident alerts. With this look and feel you could really assume you are a SOC analyst in one of a big firm or corporation with delpoyed EDR, SIEM and Case management in place.
Without further ado let’s start solving 1 of the alerts related to LOLBINs.

#letsdefendio #blueteam #soc #incidentresponse