Wireshark
TryHackMe: Wireshark Traffic Analysis — Complete Walkthrough
The full traffic analysis room, from capture filters through to isolating malicious flows.
Read on Medium — TryHackMe: Wireshark Traffic Analysis — Complete WalkthroughWriting
Detailed write-ups from TryHackMe rooms, live detection labs and certification prep. Everything is published in full on Medium.
Follow on MediumWireshark
The full traffic analysis room, from capture filters through to isolating malicious flows.
Read on Medium — TryHackMe: Wireshark Traffic Analysis — Complete WalkthroughWireshark
Packet operations in depth: display filters, statistics, stream following and exporting objects.
Read on Medium — Mastering Wireshark Packet OperationsZeek
Using Zeek logs to trace anomalies, detect Log4j exploitation and surface phishing activity.
Read on Medium — TryHackMe: Zeek Exercises — Network Analysis WalkthroughSnort
Running Snort in live IPS mode and writing reject rules against active brute-force and reverse shells.
Read on Medium — TryHackMe: Snort Challenge — Live AttacksSnort
Rule syntax fundamentals: building detections from scratch and validating them against captured traffic.
Read on Medium — TryHackMe: Snort Challenge — The BasicsMalware Analysis
A malware analysis and threat intelligence CTF worked end to end, with tooling notes throughout.
Read on Medium — Friday Overtime — TryHackMe CTF WalkthroughThreat Intel
Operationalising MISP: ingesting feeds, correlating events and pivoting on indicators.
Read on Medium — Threat Intel with MISP — TryHackMe WalkthroughDetection
Generating YARA rules with yarGen, scanning with Loki and validating hits against threat intel.
Read on Medium — Detecting Web Shells with YARA & LokiRed Team
Practical web exploitation and ethical hacking techniques from a hands-on Red Team internship.
Read on Medium — My Red Team Internship JourneyMITRE ATT&CK
Mapping APT28 tradecraft onto the ATT&CK matrix to drive detection and response decisions.
Read on Medium — TryHackMe: Eviction — Tracking APT28 with MITRE ATT&CK