Blog topic // Curated

Digital Forensics

These case studies show how to move from raw evidence to supported findings. They cover packet analysis, covert-channel reconstruction, malware behavior, and the process of correlating files, processes, registry activity, and network traffic without overstating what the evidence proves.

5 min

After Hours | TryHackMe Room Writeup

A walkthrough of After Hours, a TryHackMe forensics challenge involving a Windows WMI repository, a custom class, raw DEFLATE, and a .NET payload.

  • TryHackMe
  • Digital Forensics
  • Windows
  • WMI
4 min

Packed Light | TryHackMe Room Writeup

A beginner-friendly walkthrough of Packed Light, a TryHackMe network forensics challenge about recovering XOR-encrypted keystrokes from HTTP cookies.

  • TryHackMe
  • Network Forensics
  • Wireshark
  • PCAP
Case study · 4 min

WannaCry Malware Analysis

Static and dynamic analysis of a WannaCry sample in an isolated Windows environment, with correlated process, file, registry, and network evidence.

  • ANY.RUN
  • Binary Ninja
  • ProcMon
  • Process Explorer