Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting

NetwerkLABS

Powered By TEKGENX CONSULTING

  • Home
  • BLUE TEAM
    • MITRE ATT&CK
    • INFOSEC Governance and Regulation
      • NIST
        • IDENTIFY
        • PROTECT
        • DETECT
        • RESPOND
        • RECOVER
      • Risk Management
    • SOC
      • Threat Detection and Incident Response
        • Threat Detection EngineeringA practical course on Threat Detection Engineering using Elastic SIEM/EDR
        • Threat Hunting
          • Traffic Analysis
        • Splunk
          • Splunk Basics
          • Understanding Log Sources
          • Dashboards and Reports
          • Exploring SPL
          • Incident Handling with Splunk
          • Investigating with Splunk
    • Security+
    • Scripting
      • Bash Scripting
      • Python
      • ZyBER-TOOLS
  • ZyBER-SERIES
    • Wazuh – SIEM and XDRThe Open Source Security Platform that provides Unified XDR and SIEM protection for endpoints and cloud workloads
    • Attack and Defend Active Directory
    • Offensive Testing Enterprise Networks
    • Threat Detection EngineeringA practical course on Threat Detection Engineering using Elastic SIEM/EDR
    • F5 Local Traffic Manager (LTM)F5 Local Traffic Manager (LTM)
    • Incident Response and Forensics
    • Red Team Engagements
  • ZyBER-INTEL
  • ZyBER-NEWS
  • Cookie Policy (EU)
Subscribe
Top Stories
HAVOC C2: COMMAND & CONTROL FRAMEWORK [PART – I]
Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]
SETUP DVWA ON WINDOWS
Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]
Wireshark Threat Hunting – From Packets to Indicators
Nmap Cheat Sheet
The Bait Lab – Phishing Simulations, Practical Campaigns with GoPhish & Evilginx (PART: II)
The Bait Lab – Phishing Simulations, Practical Campaigns with GoPhish & Evilginx (PART: I)
RED Teaming: Mythic C2 Framework
Installing OpenBAS: The OpenSource Breach and Attack Simulation
Metasploit Framework (MSFconsole) Cheatsheet
OpenCTI – Open Source Threat Intelligence Platform: PART I
SIEM: Onboarding WIndows Servers
Command & Control Mastery with Covenant C2: PART-I
Active Directory Enumeration with PowerView
TryHackMe: PyRAT
Install Docker on ParrotOS
Hunting the hunters: DFIR with Velociraptor (PART-II)
Hunting the hunters: DFIR with Velociraptor (PART-I)
Caldera: Simulating a Complete Attack Chain
Installing Caldera on ParrotOS: A Smoother Experience Compared to Ubuntu and Kali Linux
Vulnerability Management: FARADAY
Atomic Red Team – A Framework for Threat Emulation: PART II
Atomic Red Team – A Framework for Threat Emulation: PART I
Data Manipulation in Splunk: PART II
Data Manipulation in Splunk: PART I
Regular Expressions
Active Directory Domain Service (AD DS)
GRC 101: SimpleRisk Core (Community Edition)
Metasploit Cheat Sheet
Shodan 101
Wireshark 101 | Traffic Analysis and Investigation (PART 04)
Wireshark 101 | Traffic Analysis and Investigation (PART 03)
Concepts of Forensic Imaging
Wireshark 101 | Traffic Analysis and Investigation (PART 02)
Wireshark 101 | Traffic Analysis and Investigation (PART 01)
Endpoint Detection and Response (EDR) : Lima Charlie (Part 01)
SNORT 101 (Part 03)
SNORT 101 (Part 02)
Snort 101 (Part 01)
Splunk SIEM: Search Processing Language (SPL) Basics
 Ship OPNSense Firewall Logs To Splunk SIEM
Wazuh: VirusTotal Integration
Operationalizing Security: CALDERA Meets WAZUH (PART II)
Operationalizing Security: CALDERA Meets WAZUH (PART I)
(TryHackMe) Servidae: Log Analysis in ELK
TD_003
Threat Detection Engineering
Log Analysis: Basics
Splunk SIEM: Exploring SPL
Threat Intelligence with MISP: Part 1 – Setting up MISP with Docker
Thraet_Detect_TWO
Useful Windows Event IDs
Yara
Web Attacks
close up view of system hacking
NIST Cybersecurity Framework (CSF) and ISO/IEC 27001
close up view of system hacking
Digital Operational Resilience Act (DORA)
Test Page
CTI_June2024: Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
TD_003
Wazuh: Detecting Web Attacks
TD_003
Ingesting OPNsense logs into Wazuh SIEM
THREAT EMULATION: Introduction
Decoding
IR_002
Code Obfuscation and Deobfuscation
Incident Response
Remote Monitoring and Management software used in phishing attacks
Pyramid of Pain
MISP (Malware Information Sharing Platform)
SOC Home LAB: Elastic SIEM Installation
Incident Report Template
Windows Event Logs
Wireshark 101 | Packet Operations
SOC Tools and Useful Links
ELASTIC SIEM: Kibana Query Language (KQL) 
MITRE Framework
GOAD v2 Installation
DFIR: Core Windows Processes
Remotely Upgrading Wazuh Agents – CLI Method
L4 – L7 Load Balancing
BIG-IP LTM: Deployment Models
BIG-IP LTM: Load Balancing Methods
Threat Intelligence for SOC
Threat Detection: Detecting a Webserver Attack
Detection Engineering vs Threat Hunting
Linux System Hardening
DFIR: Linux File System Analysis
Yara 101
NetworkMiner
TCPView
Intro to Practical Enterprise Pentesting
High-Risk Vulnerabilities in ConnectWise ScreenConnect and Remediation procedure
AD Attacks & Tools Timeline
AD Fundamentals
Breaching AD
Cyber Kill Chain
Splunk SPL 101
Practical Threat Hunting using Elastic SIEM: Hunting for Stuxbot
Netminer
Introduction to Network Forensics
Wireshark: 802.11 Denial of Service
Analysis with Wireshark
TCPDump
Posted inRED TEAM

HAVOC C2: COMMAND & CONTROL FRAMEWORK [PART – I]

A deep-dive into deploying and operating Havoc — the modern, open-source post-exploitation C2 framework built for red teams and purple team simulation labs. From installation and team server configuration to listener setup, payload generation, and agent…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Posted inTraffic Analysis Threat Detection and Incident Response SOC Analyst

Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]

HTTP/HTTP2 Deep-Dive — Wireshark DFIR // HTTP / HTTP2 — Deep-Dive Filter Reference Granular Wireshark display filters for HTTP/1.1 and HTTP/2 — request methods, path & file access, credential extraction, brute force detection, SQL injection, XSS,…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Posted inRED TEAM

SETUP DVWA ON WINDOWS

Introduction to DVWA Damn Vulnerable Web Application (DVWA) is one of the most widely used platforms for learning and practicing web application security testing. As the name suggests, it is a deliberately vulnerable web application designed…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Posted inTraffic Analysis Threat Detection and Incident Response SOC Analyst

Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]

SMB & Windows Auth Deep-Dive — Wireshark DFIR // SMB & Windows Auth — Deep-Dive Filter Reference Granular Wireshark display filters for SMB2 file & share access (paths, users, operations, error codes), NTLM authentication flow, Kerberos…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Posted inTraffic Analysis Threat Detection and Incident Response SOC Analyst

Wireshark Threat Hunting – From Packets to Indicators

Wireshark DFIR Cheat Sheet // Wireshark DFIR Cheat Sheet Display filters, detection techniques, traffic analysis workflows, and TShark CLI commands for Digital Forensics & Incident Response. Filters are mapped to MITRE ATT&CK where applicable. Wireshark 4.x…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Posted inRED TEAM VulnLAB Purple Teaming

Nmap Cheat Sheet

Nmap Cheat Sheet nmap — cheat sheet Network Mapper · Comprehensive Command Reference 🎯 Target Specification 8 nmap 192.168.1.1·Scan a single IP nmap 192.168.1.1-254·Scan IP range nmap 192.168.1.0/24·Scan CIDR subnet nmap 10.0.0.1 10.0.0.2·Scan multiple IPs nmap…
Continue Reading
Posted by Avatar photo Bharath Narayanasamy
Splunk SIEM: Search Processing Language (SPL) Basics
Posted inSplunk Exploring SPL

Splunk SIEM: Search Processing Language (SPL) Basics

Splunk Search Processing Language comprises of multiple functions, operators and commands that are used together to form a simple to complex search and get the desired results from the ingested logs. Main components of SPL Search…
Read More
Posted by Avatar photo Bharath Narayanasamy
 Ship OPNSense Firewall Logs To Splunk SIEM
Posted inSplunk Splunk Basics

 Ship OPNSense Firewall Logs To Splunk SIEM

Shipping OPNsense firewall logs to Splunk centralizes log management, allowing for seamless consolidation with other network and system logs. This integration enhances visibility into network traffic, enabling the identification of threats like port scans, malware communication,…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splink, OPNSense
Wazuh: VirusTotal Integration
Posted inwazuh

Wazuh: VirusTotal Integration

Wazuh Integration with VirusTotal Overview Wazuh integrates with VirusTotal to detect malicious files via the File Integrity Monitoring (FIM) module. This allows inspection of monitored files for potential threats. About VirusTotal Service Features: Analyzes files and…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: wazuh, virustotal, SIEM
Operationalizing Security: CALDERA Meets WAZUH (PART II)
Posted inThreat Detection and Incident Response RED TEAM DETECT

Operationalizing Security: CALDERA Meets WAZUH (PART II)

Adversary emulation with Caldera and Wazuh Please visit here to read PART I of this series, which explains the Caldera setup and Windows agent installation. Agent setup Deploy Agents on Linux machines Now, the lab consists…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: wazuh, caldera
Operationalizing Security: CALDERA Meets WAZUH (PART I)
Posted inRED TEAM

Operationalizing Security: CALDERA Meets WAZUH (PART I)

CALDERAâ„¢ is an open-source framework designed to run autonomous adversary emulation exercises efficiently. It enables users to emulate real-world attack scenarios and assess the effectiveness of their security defences. In addition, it provides a modular environment for…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: caldera, red-team
(TryHackMe) Servidae: Log Analysis in ELK
Posted inThreat Hunting SOC Analyst Threat Detection and Incident Response

(TryHackMe) Servidae: Log Analysis in ELK

Link to the TryHackMe Room; https://tryhackme.com/r/room/servidae Room Objectives: Get familiar with the Elastic (ELK) Stack and its components. Understand the significance of log data analysis in detecting and investigating security incidents. Get introduced to Kibana and its key…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SIEM, THM, ELK
TD_003
Posted inThreat Hunting SOC Analyst Threat Detection and Incident Response

Threat Detection Engineering

Threat Detection Engineering (TDE) involves designing, implementing, and refining security measures to identify and respond to threats. Here are some key topics and domains covered under TDE: Threat Intelligence: Gathering, analyzing, and applying information about current…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: THreat, TDE
Log Analysis: Basics
Posted inThreat Hunting SOC Analyst Intrusion Detection and Response

Log Analysis: Basics

Understanding Logs in Infrastructure Systems Logs and Their Role Logs are time-sequenced messages recording events within a system, device, or application. Essential for insights into the inner workings of infrastructure systems, offering visibility into applications, networks,…
Read More
Posted by Avatar photo Bharath Narayanasamy
Splunk SIEM: Exploring SPL
Posted inThreat Hunting SOC Analyst Threat Detection and Incident Response

Splunk SIEM: Exploring SPL

Splunk Search & Reporting App Overview The Search & Reporting App is the primary interface on Splunk's Home page used for searching and analyzing data. This app provides several essential functionalities to enhance the search experience…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SIEM
Threat Intelligence with MISP: Part 1 – Setting up MISP with Docker
Posted inCyber Threat Intelligence and Advisory Threat Hunting Threat Intelligence

Threat Intelligence with MISP: Part 1 – Setting up MISP with Docker

Step-by-Step Guide to Install MISP Using Docker on Ubuntu In this guide, we will walk through the steps to install the MISP (Malware Information Sharing Platform) using Docker on an Ubuntu server. Prerequisites Before we begin,…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: MISP, Threat Intel

Posts pagination

Previous page 1 … 3 4 5 6 7 … 18 Next page

Recent Posts

  • HAVOC C2: COMMAND & CONTROL FRAMEWORK [PART – I]
  • Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]
  • SETUP DVWA ON WINDOWS
  • Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]
  • Wireshark Threat Hunting – From Packets to Indicators

Categories

AD AD attacks brute-force caldera CISO dfir Elastic hydra linux NIST red-team SIEM snort splunk Threat Intel threat_detection Threat_hunting vulnhub wazuh wireshark

You May Have Missed
Posted inRED TEAM

HAVOC C2: COMMAND & CONTROL FRAMEWORK [PART – I]

Posted by Avatar photo Bharath Narayanasamy
Posted inTraffic Analysis Threat Detection and Incident Response SOC Analyst

Wireshark Threat Hunting – From Packets to Indicators [HTTP: DEEP-DIVE]

Posted by Avatar photo Bharath Narayanasamy
Posted inRED TEAM

SETUP DVWA ON WINDOWS

Posted by Avatar photo Bharath Narayanasamy
Posted inTraffic Analysis Threat Detection and Incident Response SOC Analyst

Wireshark Threat Hunting – From Packets to Indicators [SMB: DEEP-DIVE]

Posted by Avatar photo Bharath Narayanasamy
Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by