Vladdd52/incident-response-reports
GitHub: Vladdd52/incident-response-reports
Stars: 1 | Forks: 0
# 🛡️ Incident Response Reports
A collection of incident response and forensic analysis reports completed as part of cybersecurity lab exercises.
## 📁 Reports
| Report | Description |
|--------|-------------|
| 🌐 **Network Analysis** | Multi-stage network intrusion: reconnaissance, SQL/Command Injection, reverse shell, lateral movement, data exfiltration via DNS tunneling |
| 🔩 **Persistence Analysis** | Forensic investigation of persistence mechanisms on a compromised Linux host: malicious systemd services, cron jobs, udev rules, SSH key injection |
| 🕵️ **Threat Intelligence** | Attribution and TTP analysis of a phishing campaign delivering NetSupport RAT, linked to APT group Bloody Wolf targeting organizations in Central Asia |
| 🔍 **Wazuh Investigation** | SIEM-based investigation of a multi-stage attack on AD infrastructure: NTLM brute force, web exploitation, privilege escalation, credential dumping via Mimikatz/LaZagne |
## ⚙️ Methodology
Each report includes attack timeline, technical analysis, IOC tables, and MITRE ATT&CK mapping.
## 👤 Author
**Kobzev Vladislav** · [@eeextinct](https://t.me/eeextinct) · kvladislav1305@gmail.com
标签:APT分析, CISA项目, Cloudflare, Cron持久化, DNS隧道, forensic analysis, LaZagne, Linux安全, Mimikatz, MITRE ATT&CK, NetSupport RAT, NTLM爆破, Object Callbacks, OpenCanary, PE 加载器, SIEM, SQL注入, SSH密钥注入, Wazuh, Web报告查看器, 凭据转储, 协议分析, 反弹Shell, 命令注入, 威胁情报, 安全事件响应, 实验室报告, 库, 应急响应, 开发者工具, 情报归因, 持久化机制, 搜索语句(dork), 攻击调查, 数字取证, 数据窃取, 数据集, 权限提升, 横向移动, 活动目录安全, 漏洞利用, 系统分析, 编程规范, 网络分析, 网络安全, 网络攻防, 网络钓鱼, 自动化脚本, 蓝队, 隐私保护