Skip to content
Panagiotis Kavakopoulos

BTLO training investigations

Technical Write-ups

14 investigations showing the evidence, queries, and reasoning behind each lab answer. These document training exercises, not production incidents.

Digital Forensics

3
Digital Forensics8 min read

Indicators

The lab hands you one file, sh4, pulled off a compromised Windows server, and asks twelve questions about it.

Digital Forensics10 min read

Steam

Split VMware disks reveal a Linux Steam install hidden in a snap package path, with forensic clues spread across the image.

Digital Forensics7 min read

Sticky Situation

One disk image, ten questions, and a USB stick that left its traces all over the Windows registry.

Incident Response

3
Incident Response7 min read

Print

A PrintNightmare run against a Windows print spooler, told through one pcap and two event logs.

Incident Response9 min read

Spilled Bucket

Two AWS log sources, one Splunk instance, and an attack chain that keeps handing you the next question.

Incident Response8 min read

Splunk It

One malicious Invoice document, and the whole attack chain sits inside a single Splunk index.

Phishing Analysis

1
Phishing Analysis13 min read

Deep Phish

A Disney+ phishing email turns out to be one front door on a shared hosting box.

Security Operations

4
Security Operations9 min read

Blocker

Sysmon 14's FileBlockExecutable blocks suspicious executables before they reach disk; this lab traces Event ID 27 and builds detection rules.

Security Operations8 min read

Phishy

A single fake Office login page, and eight questions answered without leaving the browser.

Security Operations6 min read

Piggy

Four PCAPs reveal SSH data exfiltration, Trickbot command and control, cryptomining on unusual ports, and DNS tunneling.

Security Operations8 min read

Vortex

One PCAP traces a gift-card lure, a stealer's HTTP callback, and stolen credentials sent in cleartext over SMTP.

Threat Hunting

2
Threat Hunting13 min read

BOTS v1

A Splunk CTF rather than a guided lab: fifteen questions against the BOTS v1 index, where the only way through is knowing which sourcetype holds the answer.

Threat Hunting11 min read

Drilldown

A Splunk hunt follows unusual EC2 traffic from a web server through Sysmon, Suricata, VirusTotal, and a Joomla payload upload.

Threat Intelligence

1
Threat Intelligence8 min read

Foxy

The lab hands you four ThreatFox export files and calls the work intelligence analysis.