Knowledge Hub
Forensics Labs
Available entries
-
DFIR: An Introduction
--- Introductory room for the DFIR module --- ### Introduction ##  ###...
-
Warzone 1
---- You received an IDS/IPS alert. Time to triage the alert to determine if its a true positive. ----...
-
Analysing Volatile Memory
TryHackMe room
-
Autopsy
--- Learn how to use Autopsy to investigate artifacts from a disk image. Use your knowledge to investigate an employee who is being...
-
Boogeyman 1
---- A new threat actor emerges from the wild using the name Boogeyman. Are you afraid of the Boogeyman? ---- ### [Introduction] New...
-
Brim
--- Learn and practice log investigation, pcap analysis and threat hunting with Brim. ---...
-
Intro to Defensive Security
--- Introducing defensive security and related topics, such as threat intelligence, SOC, DFIR, and SIEM. --- Offensive security focuses...
-
Intro to Log Analysis
TryHackMe room
-
Intro to Malware Analysis
--- What to do when you run into a suspected malware --- ### Introduction Every once in a while, when you are working as a SOC analyst,...
-
KAPE
--- An introduction to Kroll Artifact Parser and Extractor (KAPE) for collecting and processing forensic artifacts ---...
-
Linux Forensics
--- Learn about the common forensic artifacts found in the file system of Linux Operating System ---...
-
MAL REMnux The Redux
--- A revitalised, hands-on showcase involving analysing malicious macro's, PDF's and Memory forensics of a victim of Jigsaw Ransomware;...
-
Osquery: The Basics
--- Let's cover the basics of Osquery. --- ...
-
Windows Forensics 2
--- Learn about common Windows file systems and forensic artifacts in the file systems. ---...
-
Wireshark 101
--- Learn the basics of Wireshark and how to analyze various protocols and PCAPs --- ### Introduction Wireshark, a tool used for...
-
25 Days of Cyber Security
TryHackMe room
-
Advent of Cyber 2 [2020]
TryHackMe room
-
Advent of Cyber 2022
--- Get started with Cyber Security in 24 Days - learn the basics by doing a new, beginner-friendly security challenge every day leading...
-
Advent of Cyber 2023
TryHackMe room
-
Android Malware Analysis
---- Android malware analysis with Pithus (static and hunting) --- ...
-
Overpass
``` ***gobuster*** gobuster dir --url http://10.10.101.139 --wordlist /usr/share/wordlists/dirb/common.txt (found path /admin)...
-
Phishing Emails 3
--- Learn the tools used to aid an analyst to investigate suspicious emails. ---  and (CVE-2021-34527). ---...
-
PrintNightmare, again!
--- Search the artifacts on the endpoint to determine if the employee used any of the Windows Printer Spooler vulnerabilities to elevate...
-
Red Team Threat Intel
--- Apply threat intelligence to red team engagements and adversary emulation. ---...
-
Registry Persistence Detection
TryHackMe room
-
Sandbox Evasion
--- Learn about active defense mechanisms Blue Teamers can deploy to identify adversaries in their environment. ---...
-
Servidae: Log Analysis in ELK
TryHackMe room
-
Smag Grotto
--- Follow the yellow brick road. --- ...
-
Snort Challenge - The Basics
--- Put your snort skills into practice and write snort rules to analyse live capture network traffic. --- ### Introduction...
-
Splunk 101
--- This room will cover the basics of Splunk. --- ...
-
Super-Spam
---- Defeat the evil Super-Spam, and save the day!! ---- ...
-
Wireshark: Packet Operations
--- Learn the fundamentals of packet analysis with Wireshark and how to find the needle in the haystack! ---...
-
Wireshark: The Basics
TryHackMe room
-
Wireshark: Traffic Analysis
--- Learn the basics of traffic analysis with Wireshark and how to find anomalies on your network! ---...
-
Wonderland
``` gobuster dir --url http://10.10.122.82/ --wordlist /usr/share/wordlists/dirb/common.txt -t 30 found /r then /a so /r/a/b/b/i/t...
-
Yara
--- Learn the applications and language that is Yara for everything threat intelligence, forensics, and threat hunting! ---...
-
Zeek
--- Introduction to hands-on network monitoring and threat detection with Zeek (formerly Bro). ---...
-
Abusing Windows Internals
--- Leverage windows internals components to evade common detection solutions, using modern tool-agnostic approaches. ---...
-
Advanced Static Analysis
TryHackMe room
-
Advent of Cyber 2024
TryHackMe room
-
Advent of Cyber 3 (2021)
TryHackMe room
-
Android Analysis
TryHackMe room
-
Anonymous Playground
---- Want to become part of Anonymous? They have a challenge for you. Can you get the flags and become an operative? ---- ### Task 1...
-
Anti-Reverse Engineering
TryHackMe room
-
APT28 Inception Theory
TryHackMe room
-
Atomic Bird Goes Purple #2
TryHackMe room
-
Atomic Red Team
TryHackMe room
-
Attacking ICS Plant #1
TryHackMe room
-
AV Evasion: Shellcode
--- Learn shellcode encoding, packing, binders, and crypters. --- ### Introduction In this room, we'll explore how to build and deliver...
-
AWS Lambda
TryHackMe room
-
Blizzard
TryHackMe room
-
Blog
--- Billy Joel made a Wordpress blog! --- . ----...
-
Dependency Management
--- Learn about the security concerns regarding dependency management in the automated DevOps pipeline. ---...
-
Dirty Pipe
--- This room will provide an overview of the vulnerability, as well as give you an opportunity to exploit it for yourself in the...
-
DNS
``` If you were on Windows, what command could you use to query a txt record for 'youtube.com'? nslookup -type=txt youtube.com If you...
-
DNS Manipulation
TryHackMe room
-
Dunkle Materie
TryHackMe room
-
Enumerating Active Directory
TryHackMe room
-
Eviction
TryHackMe room
-
Expediting Registry Analysis
TryHackMe room
-
FlareVM: Arsenal of Tools
TryHackMe room
-
Follina MSDT
--- A walkthrough on the CVE-2022-30190, the MSDT service, exploitation of the service vulnerability, and consequent detection...
-
Forensics
TryHackMe room
-
Hacker vs. Hacker
--- Someone has compromised this server already! Can you get in and evade their countermeasures? ---...
-
Hackfinity Battle Encore
TryHackMe room
-
HaskHell
---- Teach your CS professor that his PhD isn't in security. ---- ...
-
HeartBleed
--- SSL issues are still lurking in the wild. Can you exploit this web servers OpenSSL? ---...
-
Hosted Hypervisors
TryHackMe room
-
IDS Fundamentals
TryHackMe room
-
Ignite
--- A new start-up has a few issues with their web server. ---  and experience an ethical hacker's job. ---...
-
Intro To Pwntools
---- An introductory room for the binary exploit toolkit Pwntools. --- -[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
PC
``` ┌──(witty㉿kali)-[~/Downloads] └─$ rustscan -a 10.10.11.214 --ulimit 5500 -b 65535 -- -A -Pn .----. .-. .-. .----..---. .----. .---....
-
Phishing Prevention
TryHackMe room
-
Poster
--- The sys admin set up a rdbms in a safe way. --- -[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
-
Redeemer
``` blob:https://app.hackthebox.com/da9e33b6-5b40-44e1-851b-35f1e7f10447 ┌──(kali㉿kali)-[~] └─$ ping 10.129.87.135 PING 10.129.87.135...
-
Res
--- Hack into a vulnerable database server with an in-memory data-structure in this semi-guided challenge! ---...
-
Revil_Corp
``` ┌──(kali㉿kali)-[~/Downloads] └─$ xfreerdp /u:administrator /p:'letmein123!' /v:10.10.101.235 [17:16:55:731] [111859:111868]...
-
Runtime Detection Evasion
--- Learn how to bypass common runtime detection measures, such as AMSI, using modern tool-agnostic approaches. ---...
-
Snort
--- Learn how to use Snort to detect real-time threats, analyse recorded traffic files and identify anomalies. ---...
-
Snort Challenge - Live Attacks
--- Put your snort skills into practice and defend against a live attack --- ### Scenario 1 | Brute-Force Use the attached VM to finish...
-
Splunk: Basics
--- Learn the basics of Splunk. ---  ###...
-
Tardigrade
---- Can you find all the basic persistence mechanisms in this Linux endpoint? ----...
-
Tcpdump: The Basics
TryHackMe room
-
Templated
``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
Templated
``` ┌──(witty㉿kali)-[~/Downloads] └─$ sudo openvpn lab_wittyAle.ovpn ┌──(witty㉿kali)-[~/Downloads] └─$ ip addr | grep tun0 6: tun0: mtu...
-
The Game v2
TryHackMe room
-
The Return of the Yeti
TryHackMe room
-
Theseus
---- The first installment of the SuitGuy series of very hard challenges. ---- -[~/hackthebox] └─$ rustscan -a 10.129.72.184...
-
Void Execution
TryHackMe room
-
Windows Applications Forensics
TryHackMe room
-
Windows Fundamentals 2
TryHackMe room
-
Windows Incident Surface
TryHackMe room
-
Windows Internals
--- Learn and understand the fundamentals of how Windows operates at its core. ---...
-
Windows Local Persistence
--- Learn the most common persistence techniques used on Windows machines. --- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/1...
-
Windows Memory & Processes
TryHackMe room
-
Windows PrivEsc
TryHackMe room
-
Windows Reversing Intro
---- Introduction to reverse engineering x64 Windows software. ---- ![](https://tryhackme-images.s3.amazonaws.com/room-icons/e1566084619a...
-
Windows User Account Forensics
TryHackMe room
-
Wreath
---- Learn how to pivot through a network by compromising a public facing web machine and tunnelling your traffic to access other...
-
x86 Architecture Overview
---- A crash course in x86 architecture to enable us in malware reverse engineering. ----...
-
x86 Assembly Crash Course
TryHackMe room
-
XXE Injection
TryHackMe room
-
Zeek Exercises
--- Put your Zeek skills into practice and analyse network traffic. --- ![](https://tryhackme-images.s3.amazonaws.com/user-uploads/613113...