I Automated My Incident Response
I built a Python bot that monitors my Linux server, detects SSH brute force and web shell scanning, sends Slack alerts, and auto-blocks attackers via UFW.
I built a Python bot that monitors my Linux server, detects SSH brute force and web shell scanning, sends Slack alerts, and auto-blocks attackers via UFW.
A hands-on walkthrough of LetsDefend SOC338. Lumma Stealer delivered via ClickFix phishing and DLL side-loading. Real investigation steps, MITRE tags, and verdict.
Some support tickets look routine but might be early signs of account compromise, phishing, or malware. Here are 7 ticket types worth a second look, plus what to document and when to escalate.
Three platforms. Three different types of security professional. LetsDefend builds SOC analysts. TryHackMe builds ethical hackers. Hack The Box builds red teamers.
Here is how to pick the right one for where you want to go, and why the best practitioners use more than one.
A full SOC analyst walkthrough of LetsDefend alert SOC146 phishing email delivering Excel 4.0 XLM macros, DLL loading via regsvr32, and confirmed C2 beaconing. MITRE ATT&CK mapped, verdict explained.