LetsDefend SOC130 walkthrough: Event Log Cleared on an Exchange server
A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.
A LetsDefend SOC130 case where cleared logs, a backdoor account, and a fake powershell.exe led to a true positive VirusTotal missed.
A hands-on walkthrough of LetsDefend SOC137. Macro-enabled .docm file with obfuscated PowerShell, sandbox evasion, process injection, and MRU deletion. True Positive.
A hands-on walkthrough of LetsDefend SOC338. Lumma Stealer delivered via ClickFix phishing and DLL side-loading. Real investigation steps, MITRE tags, and verdict.
I installed Splunk on my own production server to build real SOC skills. Here’s what I found already probing my server, and how I locked myself out with my own detection stack.