Blog
Technical insights on SIEM, EDR, and Blue Team operations from the SOC
7 posts
An IRS-Themed Lure Installing Signed RMM Tooling
A user ran a file called ID.me_IRS_VM_REC_Secure_Verification_Gateway-1664459__<date>-166445992WW.EXE out of their Downloads folder, and what followed was a chain of software installations that each c…
Read MoreWhen "ollama.js" Isn't Ollama
A file named ollama.js came off a host that already had a working Ollama installation, which put both the file name and the application in line with ordinary setup activity. The one thing that did not…
Read MoreBuilding Threatweave
A few months ago I was triaging a suspicious IP with VirusTotal, AbuseIPDB, Shodan, and OTX open in four tabs, reconciling the results by hand for something like the hundredth time. Threatweave is wha…
Read MoreBuilding a Security-Focused Homelab: Lessons from Week One
Starting my homelab journey has been more rewarding than I expected. After researching budget options, I settled on a Dell OptiPlex 7070 with 16GB of RAM, 256GB of storage, and an Intel i5 8500T. It’s…
Read MoreActive Node.js Malware Campaign Targeting Manual Reader Applications
We’re seeing a significant uptick in a malware campaign that’s affecting multiple customers. This one’s worth knowing about if you’re in a SOC or working with EDR platforms. Attackers are distributing…
Read MoreBuilding Effective Threat Hunting Queries
Automated detections cover the behavior somebody already wrote a rule for. Hunting queries are for everything else, and the ones that work start from a specific idea about adversary behavior rather th…
Read MoreWelcome to my blog
I’m Elmer Phillips, a Security Analyst working in Managed Detection & Response at At-Bay. This blog is where I share practical notes from the SOC. Detection engineering, SIEM queries, threat hunting t…
Read More
No posts found
Try different search terms.