These notes are intended to show my thought process, methodology, and note-taking approach. The alerts will come from platforms like LetsDefend, KC7, and Splunk BoTC.
These notes will span from early 2024 to the present, and you will see the methodology evolve. Earlier notes focused on artifact collection and closure, while later ones reflect a more structured timeline approach and incorporate advice from working SMEs and practitioners.
For Let’sDefend notes, there will be tags for T1/T2 or for Security Analyst/Incident Responder. These tags indicate which cases I handle with basic triage (T1) or with deep-dive, comprehensive investigations (T2).
LetsDefend Event ID 278
Tags: Suspicious Base64 Encoding/Decoding Commands Detected, Incident Responder/T2
Investigation Date: 2/11/2026
LetsDefend Event ID 182
Tags: Possible MalDoc in PDF was Detected, Incident Responder/T2
Investigation Date: 12/4/2024
LetsDefend Event ID 198
Tags: Unauthorized Access – Hack Tool Executed, Incident Responder/T2
Investigation Date: 11/5/2024
LetsDefend Event ID 292
Tags: Unauthorized Access to NTDS.dit File Detected, Incident Responder/T2
Investigation Date: 9/6/2024
LetsDefend Event ID 78
Tags: Meterpreter or Empire activity detected, Security Analyst/T1
Investigation Date: 8/29/2024
LetsDefend Event ID 89
Tags: Multiple 500 Resp Codes, Security Analyst/T1
Investigation Date: 8/23/2024
