Investigating Suspicious Encoded PowerShell Execution
Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.
Practical security investigations, detection exercises, and lab write-ups documenting the evidence, tools, methodology, findings, and lessons from each exercise.
All investigations documented below were conducted in dedicated, isolated training sandboxes or home lab environments. All indicators, usernames, and systems are simulated or sanitized.
Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.
Investigation of over 12,000 failed SSH authentication attempts on an internet-facing Linux bastion host, identifying dictionary brute-force patterns and misconfigured firewall rules.
Dissection of an obfuscated SVG/HTML attachment designed to steal Microsoft 365 credentials through credential harvesting and iframe cloaking.
Analysis of network flow logs and Suricata NIDS alerts detecting horizontal TCP SYN sweep activity from an unauthorized development workstation.
Log analysis and triage of blind Boolean-based SQL injection attempts against a vulnerable plugin endpoint on a WordPress web server.
All investigations published here were conducted in isolated sandboxes, dedicated virtual test machines, or authorized training subnets. Sensitive organizational identifiers and IP ranges are sanitized.