ESC
Start typing to search...

Posts

DFIR

Decoding OWA Ids in On-Prem Exchange

How to decode OWA Id parameters from IIS logs to extract the PR_ENTRYID and identify specifically which emails were accessed in an on-prem Exchange environment.

May 20, 2025 6 min read
Honeypots

Honeypot Diaries: SSH Authorized Keys

Analyzing threat actor activity and malware observed in geographically dispersed honeypots.

Apr 16, 2023 4 min read
SIEM

Migrating Splunk Storage to S3 SmartStore

A short guide on how I transitioned an existing Splunk deployment to S3 SmartStore to decouple and scale storage.

Apr 01, 2023 6 min read
Information Security

Managing Password Hygiene

Reviewing the current state of password hygiene and why unique, long, and complex passwords are more important than ever.

Mar 01, 2023 4 min read
CryptoCurrency

Email Spam: Forgotten Bitcoin

This post investigates a Bitcoin recovery email scam step-by-step, exposing how it uses Google Apps Script to bypass filters, a chatbot manager persona, and a fraudulent conversion fee to steal funds.

Jan 20, 2023 6 min read
Network Security

Detecting Default Meterpreter HTTPS Listeners

Detecting default Meterpreter HTTPS listeners by fingerprinting TLS certificate metadata, cipher suites, and HTTP response bodies using Nmap, Zeek, Splunk, and Elastic.

Jul 31, 2022 7 min read
Honeypots

Honeypot Diaries: Masscan

A honeypot observations post documenting a threat actor attempting to install and use the masscan port scanner on a compromised host to scan for RDP and SSH targets, with SSH hardening mitigations.

Jun 06, 2022 8 min read
Information Security

Setup and Securing Winlogbeat

Setting up Winlogbeat 8.0 with TLS communication and keystore-based credential management, following the principle of least privilege with role-based API keys.

Feb 21, 2022 8 min read
Information Security

Ingesting PCAP Files with Zeek and Splunk

How to safely ingest and analyze pcap files at scale using Zeek and Splunk.

Feb 01, 2022 8 min read
CryptoCurrency

Cryptocurrency Pump & Dumps

This post exposes cryptocurrency pump-and-dump schemes operating on Discord, explaining how organizers pre-position before signaling group buys of low-cap coins and leave retail participants holding losses.

Jul 22, 2021 3 min read