Posts by himanshu.modi2021

@himanshu.modi2021

Himanshu Kumar Modi

himanshumodi.vercel.app Joined April 2026
151 Points3 Badges0 Connections0 Followers0 Following

Posts by himanshu.modi2021

himanshu.modi2021 in Articles 4 min read
date: 2026-03-20 description: A walkthrough of my first real malware PCAP investigation — how Ursnif used .avi file extensions to disguise DLL payloads, TLS C2 beaconing, and how I mapped the full attack to MITRE ATT&CK with Splunk detection rules. ...
post-cover-14178
himanshu.modi2021 in Articles 3 min read
description: How I identified Cobalt Strike C2 servers using Host header masquerading detection, found 3 payload domains via time-bounded TLS SNI hunting, and traced a malspam campaign — all from a single PCAP in the TryHackMe Carnage room. tags: se...
chevron_left

Latest Jobs

View all jobs →