32 Hertz SOC
Practical security operations, detection engineering, and incident response
Latest Articles
-
Phishing Investigations, Part 6
This is a continuation of Phishing Investigations, Part 5. So, in the last part of the investigation, we ended while I was searching for information about the email addresses sending me the suspicious links to view photos. I searched each of the 17 email addresses three ways. First, I searched for each full email address…
-
Phishing Investigations, Part 5
This is a continuation of Phishing Investigations, Part 4. In this next part of the investigation, I am going to take a look at the timestamps to see if there is a pattern we can identify that might be helpful. I looked through each of the emails I received. Inside each one was an “On…
-
Phishing Investigations, Part 4: Researching the Email Links
This is a continuation of Phishing Investigations, Part 3. If you are new here, you can start at the beginning. Researching the email links When I analyzed each of the phishing emails in my folder last time, one of the things I noticed was that every email contained a link I was supposed to follow…
-
Phishing Investigations, Part 3: Building a Campaign Fingerprint
This article continues Phishing Investigations, Part 2, where I sorted the suspicious messages and developed a working theory about the campaign. To begin the technical analysis of the emails I have labeled the “John Doe” messages, I created a table in my private database. A spreadsheet would work just as well, but I wanted one…
-
Phishing Investigations, Part 2: Sorting the Spam Messages
This article continues Phishing Investigations, Part 1, where I described how I began collecting suspicious messages for safe analysis. Sorting the Spam Messages After reviewing approximately 120 spam emails by hand, I was surprised—and somewhat relieved—to find that only about 17 appeared questionable enough to justify a deeper investigation. Most of the remaining messages were…
-
Phishing Investigations, Part 1
After completing the SOC Level 1 learning path on TryHackMe, I wanted to move beyond simulations and practice defensive work using real data. Artificial intelligence can assist with repetitive tasks such as reviewing large quantities of logs, but analysts still provide context, verification, documentation, and judgment. I want to strengthen that human side of the…
