Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting
NetwerkLABS

Powered By TEKGENX CONSULTING

  • ATTACK
    • PenTest
    • Web Pentest
    • C2 Frameworks
    • VulnLAB
  • DETECT
    • Detection Engineering
    • DFIR
    • EDR | SIEM | SOAR
    • Purple Teaming
    • MITRE ATT&CK
  • DEFEND
    • CTEM
    • Attack Surface Management (ASM)
    • Network Infrastructure
    • Vulnerability Management
    • WAF | Firewalls | IDS/IPS
  • LEARNING PATHS
    • Wazuh SIEM & XDR
    • Attack & Defend AD
    • Cheat Sheets
  • GRC
    • ISO/IEC 27001
    • NIS2 | CyFUN
    • NIST
    • CIS Controls
  • CTI
    • Threat Intel
    • CyBER-NEWS
Subscribe

dfir

  • Home
  • dfir
Hunting the hunters: DFIR with Velociraptor (PART-II)
Posted inDFIR

Hunting the hunters: DFIR with Velociraptor (PART-II)

We covered the deployment of Velociraptor Server and Client components in the first part of this series. You can read it here if you're interested. This part of the series will walk you through the capabilities…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: threat_detection, dfir, Velociraptor
Hunting the hunters: DFIR with Velociraptor (PART-I)
Posted inDFIR

Hunting the hunters: DFIR with Velociraptor (PART-I)

Introduction In the ever-evolving world of Digital Forensics and Incident Response (DFIR), having a powerful tool at your disposal is essential. Velociraptor stands out as an advanced, open-source endpoint monitoring, digital forensics, and cyber response platform.…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Velociraptor, dfir
Wireshark 101 | Traffic Analysis and Investigation (PART 03)
Posted inIDENTIFY DETECT RESPOND

Wireshark 101 | Traffic Analysis and Investigation (PART 03)

Investigate Tunnelling Traffic: ICMP and DNS Traffic tunnelling is (also known as "port forwarding") transferring the data/resources in a secure method to network segments and zones. It can be used for "internet to private networks" and "private networks…
Read More
Posted by Avatar photo zyberbkay Tags: wireshark, dfir
Concepts of Forensic Imaging
Posted inDFIR

Concepts of Forensic Imaging

Core Concepts The process of imaging a disk starts by identifying the target drive, preparing it for imaging, and then creating the image file which is later verified for integrity. This needs to be performed in…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: dfir
IR_002
Posted inCyBER Tools

Code Obfuscation and Deobfuscation

Code Obfuscation is a technique used to make a script more difficult to read by humans but allows it to function the same from a technical point of view, though performance may be slower. This is…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: dfir, Code
Incident Response
Posted inVulnLAB CyBER Tools

Incident Response

Incident response, also known as incident handling, is a cyber security function that uses various methodologies, tools and techniques to detect and manage adversarial attacks while minimizing impact, recovery time and total operating costs. Addressing attacks…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: dfir, IR, Incident
DFIR: Core Windows Processes
Posted inCyBER Tools

DFIR: Core Windows Processes

Reference: TryHackMe Room "Core Windows Processes" Core Windows Processes Understanding how the Windows operating system functions as a defender is vital.  Task Manager doesn't show a Parent-Child process view. That is where other utilities, such as Process…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Volatility, dfir, memory
DFIR: Linux File System Analysis
Posted inSOC Analyst Threat Detection and Incident Response Intrusion Detection and Response

DFIR: Linux File System Analysis

Read More
Posted by Avatar photo Bharath Narayanasamy Tags: incident response, detection, dfir, linux
Netminer
Posted inThreat Detection and Incident Response BLUE TEAM DETECT

Netminer

NetworkMiner CapabilityDescriptionTraffic sniffingIt can intercept the traffic, sniff it, and collect and log packets that pass through the network.Parsing PCAP filesIt can parse pcap files and show the content of the packets in detail.Protocol analysisIt can identify the…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Threat_hunting, threat_detection, netminer, dfir
Posted inBLUE TEAM DETECT Traffic Analysis

Introduction to Network Forensics

Source: Tryhackme Networkminer room Introduction to Network Forensics Network Forensics is a specific subdomain of the Forensics domain, and it focuses on network traffic investigation. Network Forensics discipline covers the work done to access information transmitted…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: BLUE, networkminer, traffic_analysis, threat_detection, dfir

Posts pagination

1 2 Next page

Recent Posts

  • Stakeholder-Specific Vulnerability Categorization
  • NIS2 to ISO 27001:2022 Mapping Table
  • NetBox Labs: Bringing Clarity and Control to Modern Network Infrastructure
  • CyFUN Implementation: A Practical Roadmap
  • XSS vs SSRF: Two Different Trust Boundaries, Two Different Attacks

Categories

AD AD attacks brute-force caldera CISO dfir Elastic hydra linux NIST red-team SIEM snort splunk Threat Intel threat_detection Threat_hunting vulnhub wazuh wireshark

Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by