Skip to content

lamontsession/investigation-analysis

Repository files navigation

investigation-analysis

This repo provides a walkthrough on the most enlightening cyber security investigations I have worked on throughout my cyber security career. These investigations cover a wide range of topics, including malware analysis, network forensics, and incident response.

Each investigation is presented in a detailed and structured manner, highlighting the key findings, methodologies used, and lessons learned. The goal of this repository is to share knowledge and insights gained from real-world cyber security investigations, helping others to understand the complexities of cyber threats and how to effectively respond to them.

Whether you are a seasoned cyber security professional or just starting out in the field, this repository offers valuable insights and practical examples to enhance your understanding of cyber security investigations.

Contents

This repository is divided up based on the security tool the investigation was triggered by:

  • crowdstrike: Investigations triggered by CrowdStrike detections
  • carbonblack: Investigations triggered by Carbon Black detections
  • extrahop: Investigations triggered by ExtraHop detections
  • zeek: Investigations triggered by Zeek detections
  • dragos: Investigations triggered by Dragos detections
  • aws-guardduty: Investigations triggered by AWS GuardDuty detections
  • ms-defender: Investigations triggered by Microsoft Defender detections/alerts
  • azure-sentinel: Investigations triggered by Azure Sentinel detections
  • splunk: Investigations triggered by Splunk correlation search detections
  • threat-hunting: Investigations triggered by proactive threat hunting activities
  • user-reports: Investigations triggered by user-reported suspicious activity
  • phishing: Investigations triggered by phishing email detections
  • entro: Investigations triggered by Entro detections (human and/or non-human identity behavior)
  • contrast: Investigations triggered by Contrast Security detections (application security)
  • cortex-cloud: Investigations triggered by Cortex Cloud detections (formerly prisma cloud)

Contributing

  1. Fork the repository
  2. Create your additions branch (git checkout -b additions/programV2)
  3. Commit your changes (git commit -m 'Added some new features')
  4. Push to the branch (git push origin additions/programV2)
  5. Open a Pull Request

License

This project is licensed under the MIT License - see the LICENSE file for details.

Author

LaMont Session

Last Updated

2026-03-22

About

This repo provides a walkthrough on the most enlightening cyber security investigations I have worked on throughout my cyber security career.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors