HTB Sherlock ProcNet writeup analyzing a simulated Sliver C2 intrusion through PCAP and API Monitor data, covering JA3 fingerprinting, execute-assembly, credential access, lateral movement, and NTDS.dit dumping.
Forensics write-ups for HTB Business CTF 2026: Project Nightfall, covering USB payloads, supply-chain compromise, Windows artifacts, ransomware
HTB Sherlock Caught writeup covering Active Directory DFIR, malicious shortcut analysis, Sliver C2, credential dumping, GPO abuse, and WMI persistence.
HTB Sherlock Hunter writeup covering lateral movement, credential attacks, PCAP analysis, KAPE triage, Autopsy, KeePass, and incident response.
HTB Sherlock Easy Money writeup covering giveaway lure malware, Yandex Browser CVE clues, PowerShell, DLL hijacking, and Windows forensics.
HTB Sherlock SillyEli writeup covering BYOD compromise, fake MS Teams installer malware, PowerShell, scheduled tasks, and reverse shell analysis.
HTB Sherlock Novitas writeup covering memory forensics, malware behavior, Volatility triage, .NET reverse engineering, and Windows compromise.
HTB Sherlock Safecracker writeup covering ransomware investigation, Windows and WSL artifacts, malware analysis, timeline reconstruction, and IOCs.
Search all indexed posts and pages. Shortcut: Ctrl K
Wheel to zoom - drag to pan - double-click reset