Securus Journal

Incident Journal: Events & Experiences

Working notes from investigations and detection engineering, mapped to the NIST incident response lifecycle.

A running log of investigations, detections, and the automation that falls out of them. Each entry maps to a phase of the NIST incident response lifecycle: what triggered it, how it was scoped, and what closed it out.


Entry 001: Phishing Investigation

Date: 2025-05-13
Phase: Detection & Analysis
Tools: Outlook, VirusTotal

A user reported an email impersonating HR with an “updated benefits enrollment” prompt. Lookalike sender address, a button pointing at a credential-harvesting page, and a broad internal distribution list that put it in front of several other mailboxes.

Investigation:

  • Pulled full headers in Outlook; the sender domain was spoofed.
  • Ran the embedded URL and its registrant domain through VirusTotal: flagged, and registered days earlier with no tie to the organization.
  • Searched mailboxes for the same message to scope who else received it.

Containment:

  • Blocked the sender domain and URL at the email gateway.
  • Advisory to recipients; credential reset and forced MFA re-registration for the one user who clicked.
  • Logged the indicators (sender, subject, URL) and filed the incident.

The whole chain was confirmable in minutes with tools everyone already has. The slow part is never the analysis, it’s getting the report in the first place.


Entry 002: Malware Detection with Suricata

Date: 2025-05-15
Phase: Detection & Analysis
Tools: Suricata, Wireshark

A host on 192.168.1.x was beaconing to a known-malicious IP, consistent with C2, and existing rules were letting it through.

Response:

  • Wrote a Suricata rule against the observed pattern and destination rather than reaching for a generic signature.
  • Confirmed the match on captured packets in Wireshark before trusting it.
  • Isolated the host and re-imaged it clean.

A rule written against real captured traffic fires where a generic signature sits silent. Running Wireshark next to Suricata makes the feedback loop tight enough to tune in one sitting.


Entry 003: Brute-Force Detection in Splunk

Date: 2025-05-18
Phase: Detection & Analysis
Tools: Splunk

Built brute-force detection and a monitoring view over an authentication-log dataset with heavy failure noise.

Work:

  • Grouped failed logins by src_ip and user to pull the outliers out of the noise.
  • Time-series views to surface bursts inside short windows.
  • Threshold alerting on excessive failures per interval.
  • A dashboard consolidating the failure metrics for at-a-glance review.

Normalization is the whole game. The query is trivial once src_ip and user are consistent fields, and miserable when they aren’t.


Entry 004: File Hash Analysis

Date: 2025-05-21
Phase: Detection & Analysis
Tools: VirusTotal, Any.run, Hybrid Analysis

Triaged a SHA256 hash across three reputation and sandbox platforms to build a risk profile.

  • VirusTotal: flagged by 39 vendors.
  • Any.run: dynamic run showed ransomware behaviour, file enumeration followed by encryption.
  • Hybrid Analysis: external call patterns and file-system modifications.

VirusTotal gives you the verdict; the sandboxes give you the behaviour. The vendor count said it was bad. Any.run’s enumerate-then-encrypt sequence said what kind of bad, which is the part that changes how you respond.


Entry 005: IP Allow List Automation

Date: 2025-05-24
Phase: Preparation & Containment
Tools: Python, VS Code

Replaced a manual allow-list review, error-prone the moment the file got long, with a short Python cleanup.

  • Parsed the allow list and loaded a defined remove_list of unauthorized entries.
  • Filtered the matches and wrote the cleaned list back.
  • Structured to run on a schedule or drop into a SOAR workflow.

The value isn’t the twenty lines of Python. It’s taking a human out of a step where one typo means an outage or an open door.


Summary

Five entries across detection, containment, and preparation. The through-line is the same each time: scope it, pick the tool that answers the actual question, write down what closed it out.

Ongoing. Lateral movement, log forensics, and response automation are next.

This post is licensed under CC BY 4.0 by the author.