Knowledge Hub

Forensics Labs

Available entries

  • DFIR: An Introduction
    --- Introductory room for the DFIR module --- ### Introduction ## ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/61306d87a330...
  • Tempest
    ---- You are tasked to conduct an investigation from a workstation affected by a full attack chain. ---...
  • Velociraptor
    --- Learn Velociraptor, an advanced open-source endpoint monitoring, digital forensic and cyber response platform. ---...
  • NetworkMiner
    --- Learn how to use NetworkMiner to analyse recorded traffic files and practice network forensics activities. --- ### Room Introduction...
  • Redline
    --- Learn how to use Redline to perform memory analysis and to scan for IOCs on an endpoint. ---...
  • Secret Recipe
    --- Perform Registry Forensics to Investigate a case. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/08870f82d4ce4374cdc6fe...
  • Volatility
    --- Learn how to perform memory forensics with Volatility! --- ![](https://assets.tryhackme.com/room-banners/volatility.png) ###...
  • Warzone 1
    ---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
  • Analysing Volatile Memory
    TryHackMe room
  • Autopsy
    --- Learn how to use Autopsy to investigate artifacts from a disk image. Use your knowledge to investigate an employee who is being...
  • Boogeyman 1
    ---- A new threat actor emerges from the wild using the name Boogeyman. Are you afraid of the Boogeyman? ---- ### [Introduction] New...
  • Brim
    --- Learn and practice log investigation, pcap analysis and threat hunting with Brim. ---...
  • Intro to Defensive Security
    --- Introducing defensive security and related topics, such as threat intelligence, SOC, DFIR, and SIEM. --- Offensive security focuses...
  • Intro to Log Analysis
    TryHackMe room
  • Intro to Malware Analysis
    --- What to do when you run into a suspected malware --- ### Introduction Every once in a while, when you are working as a SOC analyst,...
  • KAPE
    --- An introduction to Kroll Artifact Parser and Extractor (KAPE) for collecting and processing forensic artifacts ---...
  • Linux Forensics
    --- Learn about the common forensic artifacts found in the file system of Linux Operating System ---...
  • MAL REMnux The Redux
    --- A revitalised, hands-on showcase involving analysing malicious macro's, PDF's and Memory forensics of a victim of Jigsaw Ransomware;...
  • Osquery: The Basics
    --- Let's cover the basics of Osquery. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5e8dd9a4a45e18443162feab/room-conte...
  • PrintNightmare, thrice!
    --- The nightmare continues.. Search the artifacts on the endpoint, again, to determine if the employee used any of the Windows Printer...
  • Pyramid Of Pain
    --- Learn what is the Pyramid of Pain and how to utilize this model to determine the level of difficulty it will cause for an adversary...
  • TheHive Project
    --- Learn how to use TheHive, a Security Incident Response Platform, to report investigation findings ---...
  • Unattended
    ---- Use your Windows forensics knowledge to investigate an incident. ---- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/635...
  • Warzone 2
    ---- You received another IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
  • Windows Forensics 1
    --- Introduction to Windows Registry Forensics --- ![](https://assets.tryhackme.com/additional/forensics1/forensics1-room-banner.png)...
  • Windows Forensics 2
    --- Learn about common Windows file systems and forensic artifacts in the file systems. ---...
  • Wireshark 101
    --- Learn the basics of Wireshark and how to analyze various protocols and PCAPs --- ### Introduction Wireshark, a tool used for...
  • 25 Days of Cyber Security
    TryHackMe room
  • Advent of Cyber 2 [2020]
    TryHackMe room
  • Advent of Cyber 2022
    --- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
  • Advent of Cyber 2023
    TryHackMe room
  • Android Malware Analysis
    ---- Android malware analysis with Pithus (static and hunting) --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/5fb4d2969a2...
  • APT28 in the Snare
    TryHackMe room
  • Basic Dynamic Analysis
    TryHackMe room
  • Basic Static Analysis
    ---- Learn basic malware analysis techniques without running the malware. --- ### Introduction In the previous rooms of this module, we...
  • CCT2019
    ---- Legacy challenges from the US Navy Cyber Competition Team 2019 Assessment sponsored by US TENTH Fleet ---...
  • Corp
    --- Bypass Windows Applocker and escalate your privileges. You will learn about kerberoasting, evading AV, bypassing applocker and...
  • Credentials Harvesting
    --- Apply current authentication models employed in modern environments to a red team approach. ---...
  • Critical
    TryHackMe room
  • CVE-2019-18634
    ``` The stack is a very regimented section of memory which stores various important aspects of a program. The heap, on the other hand,...
  • Dead End?
    TryHackMe room
  • Defensive Security Intro
    TryHackMe room
  • Digital Forensics Case B4DM755
    ---- Acquire the critical skills of evidence preservation, disk imaging, and artefact analysis for use in court. ----...
  • Digital Forensics Fundamentals
    TryHackMe room
  • Firewalls
    --- Learn about and experiment with various firewall evasion techniques, such as port hopping and port tunneling. ---...
  • Hacked
    ``` It seems like our machine got hacked by an anonymous threat actor. However, we are lucky to have a .pcap file from the attack. Can...
  • Ice
    TryHackMe room
  • Intro to Cold System Forensics
    TryHackMe room
  • Intro to Detection Engineering
    ---- Introduce the concept of detection engineering and the frameworks used towards crafting effective threat detection strategies. ----...
  • Intro to Endpoint Security
    --- Learn about fundamentals, methodology, and tooling for endpoint security monitoring. ---...
  • Introduction to SIEM
    --- An introduction to Security Information and Event Management. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/c5eca9a893...
  • iOS Forensics
    --- Learn about the data acquisition techniques and tools used in iOS device digital forensics! ---...
  • Junior Security Analyst Intro
    --- Play through a day in the life of a Junior Security Analyst, their responsibilities and qualifications needed to land a role as an...
  • L2 MAC Flooding & ARP Spoofing
    --- Learn how to use MAC Flooding to sniff traffic and ARP Cache Poisoning to manipulate network traffic as a MITM. ---...
  • Living Off the Land
    --- Learn the essential concept of "Living Off the Land" in Red Team engagements. ---...
  • Memory Acquisition
    TryHackMe room
  • Memory Analysis Introduction
    TryHackMe room
  • Memory Forensics
    TryHackMe room
  • Microsoft Windows Hardening
    --- To learn key attack vectors used by hackers and how to protect yourself using different hardening techniques. ---...
  • Mr. Phisher
    --- I received a suspicious email with a very weird looking attachment. It keeps on asking me to "enable macros". What are those? ---...
  • New Hire Old Artifacts
    ---- Investigate the intrusion attack using Splunk. ---- ![](https://assets.tryhackme.com/additional/nhoa/nhoa-banner.png)...
  • Overpass
    ``` ***gobuster*** gobuster dir --url http://10.10.101.139 --wordlist /usr/share/wordlists/dirb/common.txt (found path /admin)...
  • Phishing Emails 3
    --- Learn the tools used to aid an analyst to investigate suspicious emails. --- ![](https://assets.tryhackme.com/additional/phishing1/ph...
  • Phishing Emails 4
    --- Learn how to defend against phishing emails. --- ### Introduction DMARC es un mecanismo de autenticación de correo electrónico. Ha...
  • PrintNightmare
    --- Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527). ---...
  • PrintNightmare, again!
    --- Search the artifacts on the endpoint to determine if the employee used any of the Windows Printer Spooler vulnerabilities to elevate...
  • Red Team Threat Intel
    --- Apply threat intelligence to red team engagements and adversary emulation. ---...
  • Registry Persistence Detection
    TryHackMe room
  • Sandbox Evasion
    --- Learn about active defense mechanisms Blue Teamers can deploy to identify adversaries in their environment. ---...
  • Servidae: Log Analysis in ELK
    TryHackMe room
  • Smag Grotto
    --- Follow the yellow brick road. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/d4071f466e055d38d5a169cae9f12b33.png)...
  • Snort Challenge - The Basics
    --- Put your snort skills into practice and write snort rules to analyse live capture network traffic. --- ### Introduction...
  • Splunk 101
    --- This room will cover the basics of Splunk. --- ![](https://assets.tryhackme.com/additional/splunk-overview/splunk-room-banner.png)...
  • Super-Spam
    ---- Defeat the evil Super-Spam, and save the day!! ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/f8f1345b6e420c2f12ab1cd...
  • Sysmon
    --- Learn how to utilize Sysmon to monitor and log your endpoints and environments ---...
  • The Docker Rodeo
    --- Learn a wide variety of Docker vulnerabilities in this guided showcase. --- ![777](https://assets.tryhackme.com/room-banners/DockerPr...
  • Traffic Analysis Essentials
    --- Learn Network Security and Traffic Analysis foundations and take a step into probing network anomalies. ---...
  • Valley
    ---- Can you find your way into the Valley? ---- ![222](https://tryhackme-images.s3.amazonaws.com/room-icons/2700326f6bf2127c414a0fa45824...
  • Windows Privilege Escalation
    --- Learn the fundamentals of Windows privilege escalation techniques. --- ![](https://assets.tryhackme.com/room-banners/privesc.png)...
  • Wireshark: Packet Operations
    --- Learn the fundamentals of packet analysis with Wireshark and how to find the needle in the haystack! ---...
  • Wireshark: The Basics
    TryHackMe room
  • Wireshark: Traffic Analysis
    --- Learn the basics of traffic analysis with Wireshark and how to find anomalies on your network! ---...
  • Wonderland
    ``` gobuster dir --url http://10.10.122.82/ --wordlist /usr/share/wordlists/dirb/common.txt -t 30 found /r then /a so /r/a/b/b/i/t...
  • Yara
    --- Learn the applications and language that is Yara for everything threat intelligence, forensics, and threat hunting! ---...
  • Zeek
    --- Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro). ---...
  • Abusing Windows Internals
    --- Leverage windows internals components to evade common detection solutions, using modern tool-agnostic approaches. ---...
  • Advanced Static Analysis
    TryHackMe room
  • Advent of Cyber 2024
    TryHackMe room
  • Advent of Cyber 3 (2021)
    TryHackMe room
  • Android Analysis
    TryHackMe room
  • Anonymous Playground
    ---- Want to become part of Anonymous? They have a challenge for you. Can you get the flags and become an operative? ---- ### Task 1...
  • Anti-Reverse Engineering
    TryHackMe room
  • APT28 Inception Theory
    TryHackMe room
  • Atomic Bird Goes Purple #2
    TryHackMe room
  • Atomic Red Team
    TryHackMe room
  • Attacking ICS Plant #1
    TryHackMe room
  • AV Evasion: Shellcode
    --- Learn shellcode encoding, packing, binders, and crypters. --- ### Introduction In this room, we'll explore how to build and deliver...
  • AWS Lambda
    TryHackMe room
  • Blizzard
    TryHackMe room
  • Blog
    --- Billy Joel made a Wordpress blog! --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/618f1cc93596ff4082250bce9d869767.p...
  • Boogeyman 2
    TryHackMe room
  • Buffer Overflow Prep
    --- Practice stack based buffer overflows! --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/1948e2c67f072993904cec82f39653c0....
  • Buffer Overflows
    --- Learn how to get started with basic Buffer Overflows! --- ![|222](https://tryhackme-images.s3.amazonaws.com/room-icons/5d2d89202b5a14...
  • Burp Suite: Intruder
    --- Learn how to use Intruder to automate requests in Burp Suite --- ### Room Outline In previous rooms of this module, we have covered...
  • CAPA: The Basics
    TryHackMe room
  • Careers in Cyber
    --- Learn about the different careers in cyber security. --- ![|100](https://tryhackme-images.s3.amazonaws.com/room-icons/7934742b978f977...
  • CI/CD and Build Security
    TryHackMe room
  • ColddBox: Easy
    --- An easy level machine with multiple ways to escalate privileges. --- ### boot2Root Can you get access and get both **flags**? Good...
  • Common Linux Privesc
    --- A room explaining common Linux privilege escalation --- ### Understanding Privesc What does "privilege escalation" mean? At it's...
  • Compromised Windows Analysis
    TryHackMe room
  • Conti
    ---- An Exchange server was compromised with ransomware. Use Splunk to investigate how the attackers compromised the server. ----...
  • Core Windows Processes
    --- Explore the core processes within a Windows operating system and understand what is normal behavior. This foundational knowledge...
  • Crocc Crew
    ---- Crocc Crew has created a backdoor on a Cooctus Corp Domain Controller. We're calling in the experts to find the real back door!...
  • CVE-2023-38408
    ---- Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). ----...
  • Dependency Management
    --- Learn about the security concerns regarding dependency management in the automated DevOps pipeline. ---...
  • Dirty Pipe
    --- This room will provide an overview of the vulnerability, as well as give you an opportunity to exploit it for yourself in the...
  • DNS
    ``` If you were on Windows, what command could you use to query a txt record for 'youtube.com'? nslookup -type=txt youtube.com If you...
  • DNS Manipulation
    TryHackMe room
  • Dunkle Materie
    TryHackMe room
  • Enumerating Active Directory
    TryHackMe room
  • Eviction
    TryHackMe room
  • Expediting Registry Analysis
    TryHackMe room
  • FlareVM: Arsenal of Tools
    TryHackMe room
  • Follina MSDT
    --- A walkthrough on the CVE-2022-30190, the MSDT service, exploitation of the service vulnerability, and consequent detection...
  • Forensics
    TryHackMe room
  • Hacker vs. Hacker
    --- Someone has compromised this server already! Can you get in and evade their countermeasures? ---...
  • Hackfinity Battle Encore
    TryHackMe room
  • HaskHell
    ---- Teach your CS professor that his PhD isn't in security. ---- ![](https://i.imgur.com/4AocURG.jpg)...
  • HeartBleed
    --- SSL issues are still lurking in the wild. Can you exploit this web servers OpenSSL? ---...
  • Hosted Hypervisors
    TryHackMe room
  • IDS Fundamentals
    TryHackMe room
  • Ignite
    --- A new start-up has a few issues with their web server. --- ![|333](https://tryhackme-images.s3.amazonaws.com/room-icons/676cb3273c613...
  • Incident handling with Splunk
    --- Learn to use Splunk for incident handling through interactive scenarios. --- ### Introduction: Incident Handling This room covers an...
  • Incident Response Process
    TryHackMe room
  • Intro to C2
    --- Learn the essentials of Command and Control to help you become a better Red Teamer and simplify your next Red Team assessment! ---...
  • Intro to Digital Forensics
    TryHackMe room
  • Intro to Docker
    ---- Learn to create, build and deploy Docker containers! ---- ![](https://assets.tryhackme.com/additional/containerisation-module/Contai...
  • Intro to Offensive Security
    ---- Hack your first website (legally in a safe environment) and experience an ethical hacker's job. ---...
  • Intro To Pwntools
    ---- An introductory room for the binary exploit toolkit Pwntools. --- ![](https://raw.githubusercontent.com/Gallopsled/pwntools/stable/d...
  • Introduction to Windows API
    TryHackMe room
  • Investigating Windows 2.0
    TryHackMe room
  • Investigating Windows 3.x
    TryHackMe room
  • Investigating with ELK 101
    --- Investigate VPN logs through ELK. --- ### Introduction In this room, we will learn how to utilize the Kibana interface to search,...
  • Investigating with Splunk
    TryHackMe room
  • IR Difficulties and Challenges
    TryHackMe room
  • IR Philosophy and Ethics
    TryHackMe room
  • IR Timeline Analysis
    TryHackMe room
  • IronShade
    TryHackMe room
  • Jack
    --- Compromise a web server running Wordpress, obtain a low privileged user and escalate your privileges to root using a Python module....
  • Jacob the Boss
    ---- Find a way in and learn a little more. ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/065e4dc344a4c5fc9155dd4ae9eca52...
  • Learn Rust
    TryHackMe room
  • Legal Considerations in DFIR
    TryHackMe room
  • Linux Live Analysis
    TryHackMe room
  • Linux Logs Investigations
    TryHackMe room
  • Linux Server Forensics
    TryHackMe room
  • LinuxFunctionHooking
    ``` What are Shared Libraries? What Are Shared Libraries? Shared libraries are pre-compiled C-code that are linked during the final...
  • Logless Hunt
    TryHackMe room
  • macOS Forensics: Artefacts
    TryHackMe room
  • macOS Forensics: The Basics
    TryHackMe room
  • Masterminds
    ---- Practice analyzing malicious traffic using Brim. ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/03fe1b480ba9d32b7065f...
  • Meow
    Download vpn from lab Let the configuration script run until you see the Initialization Sequence Completed message at the very end of...
  • Meow
    Download vpn from lab What does the acronym VM stand for? *Virtual Machine * What tool do we use to interact with the operating system...
  • Metasploit
    --- Learn to use Metasploit, a tool to probe and exploit vulnerabilities on networks and servers. ---...
  • Metasploit: Meterpreter
    --- Take a deep dive into Meterpreter, and see how in-memory payloads can be used for post-exploitation. ---...
  • MISP
    --- Walkthrough on the use of MISP as a Threat Sharing Platform --- ![](https://assets.tryhackme.com/additional/jrsecanalyst/jrsec-room-b...
  • Network Security
    --- Learn about network security, understand attack methodology, and practice hacking into a target server. --- ### Introduction A...
  • Network Services 2
    --- Enumerating and Exploiting More Common Network Services & Misconfigurations --- ### Understanding NFS What is NFS? NFS stands for...
  • Networking Secure Protocols
    TryHackMe room
  • NIS - Linux Part I
    --- Enhance your Linux knowledge with this beginner friendly room! --- ![|222](https://tryhackme-images.s3.amazonaws.com/room-icons/a6046...
  • Nmap
    TryHackMe room
  • Nmap Basic Port Scans
    --- Learn in-depth how nmap TCP connect scan, TCP SYN port scan, and UDP port scan work. ---...
  • Operating System Security
    --- This room introduces users to operating system security and demonstrates SSH authentication on Linux. --- ### Introduction to...
  • Osquery
    --- Learn how to use this operating system instrumentation framework to explore operating system data by using SQL queries. ---...
  • PC
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • PC
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
  • Phishing Prevention
    TryHackMe room
  • Poster
    --- The sys admin set up a rdbms in a safe way. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/37983213b742f063a0b1fbd37a32...
  • PowerShell for Pentesters
    --- This room covers the principle uses of PowerShell in Penetration Tests. Interacting with files, scanning the network and system...
  • Protocols and Servers
    --- Learn about common protocols such as HTTP, FTP, POP3, SMTP and IMAP, along with related insecurities. --- ### Introduction This room...
  • Protocols and Servers 2
    --- Learn about attacks against passwords and cleartext traffic; explore options for mitigation via SSH and SSL/TLS. ---...
  • RazorBlack
    ``` RazorBlack These guys call themselves hackers. Can you show them who's the boss ?? Throw something like a rock on the big green...
  • Redeemer
    ``` blob:https://app.hackthebox.com/da9e33b6-5b40-44e1-851b-35f1e7f10447 ┌──(kali㉿kali)-[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
  • Redeemer
    ``` blob:https://app.hackthebox.com/da9e33b6-5b40-44e1-851b-35f1e7f10447 ┌──(kali㉿kali)-[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
  • Res
    --- Hack into a vulnerable database server with an in-memory data-structure in this semi-guided challenge! ---...
  • Revil_Corp
    ``` ┌──(kali㉿kali)-[~/Downloads] └─$ xfreerdp /u:administrator /p:'letmein123!' /v:10.10.101.235 [17:16:55:731] [111859:111868]...
  • Runtime Detection Evasion
    --- Learn how to bypass common runtime detection measures, such as AMSI, using modern tool-agnostic approaches. ---...
  • Snort
    --- Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies. ---...
  • Snort Challenge - Live Attacks
    --- Put your snort skills into practice and defend against a live attack --- ### Scenario 1 | Brute-Force Use the attached VM to finish...
  • Splunk: Basics
    --- Learn the basics of Splunk. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/2cc38529b8c7c0fa0207c71dcb8f990c.png) ###...
  • Tardigrade
    ---- Can you find all the basic persistence mechanisms in this Linux endpoint? ----...
  • Tcpdump: The Basics
    TryHackMe room
  • Templated
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
  • Templated
    ``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
  • The Game v2
    TryHackMe room
  • The Return of the Yeti
    TryHackMe room
  • Theseus
    ---- The first installment of the SuitGuy series of very hard challenges. ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/9...
  • Threat Hunting With YARA
    TryHackMe room
  • Threat Hunting: Foothold
    TryHackMe room
  • Tony the Tiger
    --- Learn how to use a Java Serialisation attack in this boot-to-root --- ### Deploy! Start Machine Firstly, ensure you are connected to...
  • TShark
    TryHackMe room
  • TShark: CLI Wireshark Features
    TryHackMe room
  • Unified
    ``` blob:https://app.hackthebox.com/9ea72111-db61-426b-b630-0afd1ffdd8a8 ┌──(kali㉿kali)-[~/hackthebox] └─$ rustscan -a 10.129.72.184...
  • Void Execution
    TryHackMe room
  • Windows Applications Forensics
    TryHackMe room
  • Windows Fundamentals 2
    TryHackMe room
  • Windows Incident Surface
    TryHackMe room
  • Windows Internals
    --- Learn and understand the fundamentals of how Windows operates at its core. ---...
  • Windows Local Persistence
    --- Learn the most common persistence techniques used on Windows machines. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/1...
  • Windows Memory & Processes
    TryHackMe room
  • Windows PrivEsc
    TryHackMe room
  • Windows Reversing Intro
    ---- Introduction to reverse engineering x64 Windows software. ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/e1566084619a...
  • Windows User Account Forensics
    TryHackMe room
  • Wreath
    ---- Learn how to pivot through a network by compromising a public facing web machine and tunnelling your traffic to access other...
  • x86 Architecture Overview
    ---- A crash course in x86 architecture to enable us in malware reverse engineering. ----...
  • x86 Assembly Crash Course
    TryHackMe room
  • XXE Injection
    TryHackMe room
  • Zeek Exercises
    --- Put your Zeek skills into practice and analyse network traffic. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/613113...