After Hours | TryHackMe Room Writeup
A walkthrough of After Hours, a TryHackMe forensics challenge involving a Windows WMI repository, a custom class, raw DEFLATE, and a .NET payload.
Blog topic // Curated
These case studies show how to move from raw evidence to supported findings. They cover packet analysis, covert-channel reconstruction, malware behavior, and the process of correlating files, processes, registry activity, and network traffic without overstating what the evidence proves.
A walkthrough of After Hours, a TryHackMe forensics challenge involving a Windows WMI repository, a custom class, raw DEFLATE, and a .NET payload.
A beginner-friendly walkthrough of Packed Light, a TryHackMe network forensics challenge about recovering XOR-encrypted keystrokes from HTTP cookies.
Static and dynamic analysis of a WannaCry sample in an isolated Windows environment, with correlated process, file, registry, and network evidence.