A HackTheBox Sherlock Unit42 investigation walkthrough using Sysmon events to reconstruct malicious download, dropped files, and the UltraVNC infection flow.
A HackTheBox Sherlock Brutus investigation walkthrough using auth.log and wtmp to reconstruct SSH brute force, persistence, and follow-up attacker activity.