Category
Forensics
13 publications
Phishing Email Header and Artifact Analysis
A defensive guide to reading phishing headers and artifacts: Received chain, SPF/DKIM/DMARC, look-alike deception, safe link and attachment triage, and hunting.
Read →Building an Incident Response Playbook
A defender's guide to writing IR playbooks that work under pressure: lifecycle, roles and authority, detection triggers, containment trade-offs, and testing.
Read →Log Analysis for Incident Response at Scale
How defenders turn high-volume telemetry into a defensible timeline: prioritized collection, normalization, correlation, retention and detection at scale.
Read →Network Forensics with Zeek and PCAP Analysis for Defenders
A defensive guide to network forensics with Zeek and PCAP: how the tools work, the logs that matter, detecting C2 and exfiltration, and a checklist.
Read →Memory Forensics with Volatility 3: A Field Guide for Defenders
A practical, defensive field guide to memory forensics with Volatility 3: acquisition, core plugins, detecting injection and rootkits, and a checklist.
Read →
Container Forensics: Investigating Kubernetes Compromises Like a Pro
How the Basilisk team collects evidence from pods, runtime, and control plane after a suspected incident in production Kubernetes clusters.
Read →
Memory Forensics with Volatility 3: Analyzing Dumps in a Reproducible Lab
Technical memory analysis workflow with Volatility 3, sandbox-reproduced dumps and cross-validation against Rekall and MemProcFS.
Read →
macOS Incident Forensics: UnifiedLogs, FSEvents and AULR in Practice
How Basilisk collects evidence on macOS Sonoma and Sequoia using UnifiedLogs, FSEvents and AULR without trampling the incident scene.
Read →
Hunting Living-off-the-Land Binaries on Windows with KQL
Production-ready KQL queries for Microsoft Defender and Sentinel to hunt LOLBin abuse from rundll32, mshta, and certutil in real environments.
Read →
Malware Analysis in an Isolated Lab: Safe Setup with FlareVM and REMnux
How to build an air-gapped lab with FlareVM and REMnux for reverse engineering real samples without contaminating your network or burning IOCs.
Read →
Disk Crypto and Backups: VeraCrypt, LUKS and a Resilient 3-2-1 Strategy
How to encrypt disks with LUKS2 and VeraCrypt and build verified 3-2-1 backups, with a recovery plan tested in the lab.
Read →
Timeline Forensics on Windows: Plaso, Log2Timeline and KAPE in Practice
Building super-timelines of a compromised Windows 11 test VM with KAPE for triage collection and Plaso parsing 200+ artifacts.
Read →
Dependency Confusion and Typosquatting: Practical Defense for Dev Teams
How registry policies, lockfiles and scoping block malicious packages before they hit the build. Hands-on technical guide from the Basilisk team.
Read →