Week 9 down in the Cyberster Blue Team Internship! 🕵️♂️💻 This week shifted focus to Browser Forensics, LNK File Analysis & Unified Timeline Correlation — piecing together how users actually interact with a system beyond just OS-level artifacts. 🔍 What I worked on: ✅ Browser Forensics (Chrome/Edge) — acquiring & hashing SQLite databases, analyzing history, downloads, cookies & cache ✅ LNK File Analysis — parsing Windows shortcut artifacts to reconstruct recent file access, USB usage & network shares ✅ Unified Timeline Building — normalizing timestamps to UTC and merging browser, Prefetch, LNK & event log data into one master timeline ✅ Cross-Artifact Correlation — connecting browser activity → LNK access → tool output review to build a defensible investigative narrative 💡 Biggest takeaway: A single artifact tells you what happened. A unified, correlated timeline tells you the story — sequence, intent & context. Grateful for the continued mentorship from my instructor, Abdullah Zia, as I keep sharpening my Blue Team & DFIR skills! 🛡️ #CyberSecurity #DigitalForensics #DFIR #BlueTeam #Internship #BrowserForensics #TimelineAnalysis #CyberSter
Browser Forensics and Timeline Analysis in Cybersecurity Internship
More Relevant Posts
-
Week 12 of my Blue Team Internship at Cyberster — and that's a wrap. 🎓 The final week brought everything together in one real capstone investigation, an insider-threat case spanning disk, memory, and removable media: ◆ Built a multi-source case combining a primary disk image and two USB devices in Autopsy — then stepped outside it entirely for the first time to analyze a raw RAM capture ◆ Used Volatility 3 to pull live process trees, and hit a hard framework wall — the RAM dump came from a Windows XP-era machine, which Volatility 3's network plugins don't support at all. Had to pivot to Volatility 2 with the correct legacy profile instead of forcing a tool that wasn't built for the target OS ◆ Practiced subject profiling before touching evidence of wrongdoing — establishing what "normal" looked like for the user first, so later findings could be judged against a real baseline instead of assumptions ◆ Cross-referenced volatile memory against disk artifacts and external media to build a single timeline instead of three disconnected stories — the same file can leave a footprint in three different places, and each one only makes sense next to the others ◆ Traced file movement across removable storage using timestamps and hash verification, treating every timestamp as a claim that needs a second source before it goes in a report ◆ Closed the loop the same way I have all internship: findings only count once they're supported by hash values, cited artifacts, and a timeline that survives scrutiny — not by what looks suspicious on first glance The biggest lesson of the whole internship comes down to one thing: every layer — network, host, memory, media — tells a partial story, and the real skill isn't finding evidence, it's proving it holds together end to end. Twelve weeks, one lab built from scratch, and a lot of "why isn't this working" turned into "here's why it wasn't." Huge thanks to Abdullah Zia and Cyberster for a curriculum that never let a shortcut pass as an answer. Final capstone report attached below. 📎 Grateful for the journey — onward from here. 🚀 #CyberSecurity #SOC #DFIR #DigitalForensics #BlueTeam #Cyberster #Internship #IncidentResponse
To view or add a comment, sign in
-
Week 5 of my Blue Team Internship at Cyberster — done. 🍀 Spent this week on the full malware-analysis lifecycle — sample acquisition through detonation to a working detection layer and formal IR plan: ♦ Sourced two live samples from theZoo, following the connect → download → verify → airgap → analyse order strictly, hashing (SHA256/MD5) each sample the moment it was extracted ♦ Ran static analysis with file, exiftool, binwalk, and strings (ASCII + -el Unicode passes) — caught a JS dropper hiding behind a String.fromCharCode decoder, and a PE/.NET sample masquerading as a "PDF Previewer" under a fake publisher name ♦ Detonated both samples interactively inside ANY.RUN with FakeNet live, manually driving execution rather than trusting an automated report, and watching the process tree, network, registry, and file-system panels in real time ♦ Almost logged Windows' own WerFault.exe crash telemetry as C2 traffic — caught the misattribution before it made it into the IOC list ♦ Replayed the session PCAP through Suricata in offline mode and wrote custom detection rules, plus MITRE-mapped Wazuh rules in local_rules.xml, each one tied to a specific observed behaviour rather than a generic template ♦ Wrote the Incident Response Plan across all four NIST SP 800-61 phases scoped honestly to what the evidence actually supported, not the clean narrative a template would assume The biggest lesson this week? A detection rule is only as trustworthy as the evidence behind it an invented IOC to paper over a gap is worse than leaving the gap marked open. Another big thanks to Abdullah Zia and Cyberster for a curriculum that keeps forcing real judgment instead of a checklist. Full breakdown (labs, troubleshooting, screenshots) attached below. 📎 Excited for Week 6. 🚀 #CyberSecurity #SOC #MalwareAnalysis #ANYRUN #Suricata #Wazuh #IncidentResponse #InfoSec #Internship #Cyberster #BlueTeam
To view or add a comment, sign in
-
Cyberster Blue Team Internship – Week 12 This week marked the completion of Phase Two of my DFIR capstone, a full-scale insider threat investigation built around the M57.biz case. Unlike earlier labs, I was given a primary disk image, a raw memory capture, and two USB drive images, and had to work through the investigation from evidence handling to the final forensic report without knowing upfront what had happened. Here's what I worked on: • Set up a multi-source Autopsy case, hashed the evidence with MD5 and SHA-256, and ran a full ingest across the disk and both USB images. • Established a system baseline from the SOFTWARE, SYSTEM, and SAM registry hives, including hostname, timezone, installed software, and user account activity. • Profiled the subject's normal role and working pattern using file system artefacts, LNK files, and Recent Items. • Installed and configured Volatility 3 to analyse the raw memory image for processes, process relationships, network connections, and command line activity. • Correlated memory findings with disk evidence to build a consistent picture of the system's state. • Examined both USB drives, recovered deleted files, and compared timestamps across disk and USB evidence to trace data movement. • Reviewed email and browser artefacts, including working around legacy file formats that Autopsy's automated parsers could not process. • Built a Master Event Sequence normalised to a single timezone to reconstruct the incident from start to finish. The biggest lesson from this capstone was how little any single piece of evidence tells you on its own. Disk, memory, USB, and email artefacts each answer a different part of the investigation. Correlating them is what allows a more complete and defensible picture to emerge. I also learned the importance of being honest about investigative limitations. Understanding what the evidence proves, what it suggests, and what remains an open gap is a core part of credible forensic analysis. Overall, Week 12 strengthened my practical experience with Autopsy, Volatility 3, Registry Explorer, memory forensics, USB and removable media analysis, and cross-artefact timeline correlation. With the completion of this capstone, I've officially completed my Internship with Cyberster. I'm grateful for the practical experience, challenges, and knowledge I've gained throughout the internship. A special thank you to my instructor, Sir Abdullah Zia, for his continued guidance and support throughout this internship. Cyberster #CyberSecurity #DigitalForensics #DFIR #BlueTeam #MemoryForensics #IncidentResponse #Autopsy #Volatility #RegistryForensics #CybersterInternship #InformationSecurity #DigitalInvestigation
To view or add a comment, sign in
-
From Theory to Live-Fire VAPT: A 60-Day Internship Journey in Simulated Enterprise Exploitation + Video Introduction: The transition from academic cybersecurity theory to practical offensive security operations represents a critical inflection point in any security professional's development. Moosa Adnan's recently completed 60-day internship at ApexPlanet Software Pvt Ltd exemplifies this transformation, moving from classroom concepts to executing full-scope Vulnerability Assessment and Penetration Testing (VAPT) within an isolated, enterprise-emulative environment. His engagement, spanning February 11 to April 11, 2026, highlights the indispensable role of hands-on simulated labs in cultivating the technical intuition required to identify, exploit, and remediate real-world vulnerabilities across networks and web applications....
To view or add a comment, sign in
-
🎓 Wrapping up the Cyberster Blue Team Internship — Week 12 Twelve weeks ago I started this internship not knowing exactly where it would take me. Twelve weeks and two full domains later, I can say it took me further than I expected. The internship was split across two core pillars of Blue Team defense: 🔹 SOC Operations — log analysis, alert triage, detection engineering, and building the muscle memory to tell real signal from noise 🔹 Digital Forensics & Incident Response — disk, memory, and USB forensics; building an evidentiary case from raw artifacts instead of assumptions Week 12 was the capstone: a full four-part insider threat investigation — from system triage and memory analysis with Volatility, through USB and deleted-file recovery, to a final forensic report answering the three questions every investigation comes down to: what happened, who did it, and how do you prove it. The biggest lesson from this internship wasn't a tool or a command — it was learning to let the evidence lead the conclusion, not the other way around. Every finding in this report is cited back to a specific artifact, because in this field, "I think" doesn't hold up — "here's the hash, here's the timestamp, here's the match" does. Huge thanks to Abdullah Zia for the mentorship throughout this program — for pushing me to document rigorously, question my own assumptions, and treat every finding as something that has to survive scrutiny. And thanks to Cyberster for building an internship that didn't just teach tools, but taught how to think like an analyst. Full final report attached below. 📄 #CyberSecurity #BlueTeam #DigitalForensics #SOC #DFIR #Cyberster #Internship #IncidentResponse #ThreatHunting #InfoSec
To view or add a comment, sign in
-
Week 12 Complete | M57.biz DFIR Investigation |M57.biz DFIR Investigation | Cyberster Blue Team Internship 🔍 Week 12 was the final investigation — bringing disk, memory, USB, and timeline evidence together to reconstruct what happened. 📌 Part A — Disk Forensics & Profiling | Days 81–82 • Ingested and hash-verified the primary disk and two USB images in Autopsy 4.19.3 • Identified the Windows XP SP3 environment, hostname, timezone, and last-login activity • Analyzed browser activity including Python and USPTO research • Found patentauto.py on the Desktop with comments indicating an intentional background-noise function 💡 Key Learning: Sometimes the strongest evidence is found in the details left behind by the tools themselves. 📌 Part B — Memory Forensics | Days 83–85 • Analyzed a RAM capture using Volatility 3 • Investigated Firefox/MozRepl activity and running processes • Identified soffice.bin spawning multiple cmd.exe processes, indicating macro-driven command execution • Documented tool limitations for Windows XP SP3 • Correlated memory findings with disk evidence — no unexplained processes remained 💡 Key Learning: Memory shows what was happening at a specific moment, while disk evidence provides the longer history. Both are valuable. 📌 Part C — USB Exfiltration & Master Timeline | Days 86–88 • Traced an Alcor Micro Flash Drive connection • Found patentauto.py created only 17 seconds after the USB connection • Investigated renamed and hidden patent-related images • Confirmed deleted files through USB copies and hash comparison • Verified the same file using matching MD5 hash • Built a 28-event master timeline combining RAM → Disk → USB evidence 💡 Key Learning: File renaming, hiding, deletion, and USB transfer can still leave a connected forensic trail. 🎯 Final Investigation Findings: • Role: Patent Researcher — supported by USPTO research activity • Incident: Intellectual Property theft — supported by hash-matched files • Method: USB-based exfiltration — supported by device and file-system timeline evidence Final week of the Cyberster Blue Team Internship — Phase 2 completed! 🎯 🛠️ Tools Used: Autopsy 4.19.3 · Volatility 3 · Registry Explorer · md5sum · sha256sum A sincere thank you to Cyberster and my mentor Abdullah Zia for the continuous guidance, encouragement, and hands-on learning throughout this internship. I truly appreciate the knowledge, practical skills, and experience gained during this journey. 🙌 #DFIR #DigitalForensics #BlueTeam #IncidentResponse #MemoryForensics #USBForensics #Autopsy #Volatility3 #DFIRCapstone #CyberSecurityInternship #Cyberster #CyberSecurity
To view or add a comment, sign in
-
Week 9 of my Blue Team Internship at Cyberster — done. 🕵️ Spent this week off the network stack and into pure host forensics — reconstructing what actually happened on a machine after the fact: ♦ Extracted and hashed browser evidence (Chrome, Edge, Firefox, Brave) before touching it — SHA256 baseline first, analysis second, so any tool that modifies the file during parsing gets caught ♦ Went manual before automated: opened the raw SQLite tables in DB Browser to understand Chrome's WebKit-epoch timestamps vs Firefox's PRTime before trusting a parser's conversion of either ♦ Built a cross-browser timeline from BrowsingHistoryView exports — the real picture of web activity only shows up once all four browsers are merged and sorted together, not looked at one at a time ♦ Moved into LNK file analysis with LECmd — proved that volume serial number, not volume label, is the reliable way to tie a set of accessed files back to one specific USB drive ♦ Hit a real correlation bug mid-week: Nirsoft tools default to local time, EZ Tools default to UTC — merge those blind and you get phantom hour-long gaps in your timeline that look like evidence tampering but are actually just a units mismatch ♦ Caught it the same way as always: treat it as a finding worth documenting, not a blocker to route around The lesson this week: no single artifact tells the truth on its own. History says a file was downloaded, an LNK says it was opened, a timestamp says when — it's only when you line all three up on the same clock that you get an actual timeline instead of three unrelated data points. Another round of thanks to Abdullah Zia and Cyberster for structuring this as real evidence handling, not a tool tutorial. Full breakdown (report, timelines, screenshots) attached below. 📎 Onto Week 10. 🚀 #CyberSecurity #SOC #DigitalForensics #DFIR #BrowserForensics #InfoSec #Internship #Cyberster #BlueTeam
To view or add a comment, sign in
-
My application for the Pinetree SWE internship: Alibi. I forked the Solari cookbook and built an audit harness for agent-written code. It runs the code in a throwaway Solari sandbox with an audit hook attached, then produces a behavior receipt: observed file activity, network calls, processes spawned, with a PASS/FLAG verdict. My coding agents ship code they can't vouch for, so I built the check I wanted. I'm using it to audit my own coder bot first, and v0.1 is complete: eight build slices, each with an acceptance check. The README leads with honest limits: this isn't malware analysis, and PASS means "nothing suspicious observed," not "trusted." Verdicts are heuristics to focus human review, not proofs of safety. Repo is public, demo below. Would love your take. Harry Chow Solari https://lnkd.in/ge58hy_u
To view or add a comment, sign in
-
Week 8 of my Blue Team Internship at Cyberster — done. 🍀 Spent this week building a forensic baseline on my own machine before ever touching a compromised one — because you can't spot abnormal until you know what normal looks like on a system you know intimately: ◆ Parsed my live Security.evtx with EvtxECmd instead of fighting Event Viewer's XML filter view — turned raw EVTX into one filterable CSV ◆ Mapped my own physical presence using Logon Type 2 (console) and Type 7 (unlock) events — built a real working-hours timeline straight from the log, no guessing ◆ Cross-referenced every 4672 (Special Privileges Assigned) event against something I actually did — installs, elevated terminals, UAC prompts — so I know exactly what legitimate privilege escalation looks like before I ever have to spot illegitimate escalation ◆ Catalogued the background noise on purpose: SYSTEM, LOCAL SERVICE, NETWORK SERVICE, DWM, UMFD — Logon Type 5 accounts that authenticate constantly and should never get flagged ◆ Moved into Prefetch analysis with PECmd — sorted by run count, then flipped the lens entirely and hunted for anything executing from Temp, Downloads, or a non-C: drive, since path beats frequency as a red flag ◆ Hit real tooling friction mid-lab — cmd-syntax instructions breaking under PowerShell, EZ Tools binaries not living where the docs assumed — and treated it the same way as every other finding: not a blocker, just something to document and fix properly The lesson that stuck this week? Your own machine is the best training ground there is — every "normal" account, path, and logon type you learn to dismiss with confidence here is one less false positive on a real investigation. Another thanks to Abdullah Zia and Cyberster for a curriculum that keeps forcing real troubleshooting instead of a checklist. Full breakdown (event log timeline, prefetch tables, screenshots) attached below. 📎 Excited for Week 9. 🚀 #CyberSecurity #SOC #DFIR #WindowsForensics #EventLogs #Prefetch #BlueTeam #InfoSec #Internship #Cyberster
To view or add a comment, sign in
-
Excited to share Project Winnie 🍯, one of the projects I worked on during my internship at KAUST (King Abdullah University of Science and Technology) The project focused on building and testing a honeypot-based security monitoring system using OpenCanary. As part of the project, we: • Built an isolated honeypot lab using Proxmox • Configured Ubuntu Server as the honeypot and Kali Linux as the attacker • Deployed multiple OpenCanary services, including SSH, FTP, HTTP/S, SMB, and Telnet • Simulated attacks such as network scanning, login attempts, and FTP brute-forcing • Analyzed the security events and logs generated by OpenCanary • Implemented real-time Microsoft Teams alerts for detected activity A big thank you to my fellow interns Layan Mashraie and Deema Alnasser for all the work we put into this project together. This project was a great opportunity to turn cybersecurity concepts into something practical and gain hands-on experience with honeypots, network security, Linux, attack simulation, security monitoring, and automation. We also had the opportunity to present Project Winnie at the WISER Expo, where interns from the WISER program across different departments came together to showcase the projects they worked on throughout their internships. It was a great way to wrap up the experience, share what we built, and see the work of other interns across the organization. #Cybersecurity #Honeypot #OpenCanary #NetworkSecurity #CybersecurityInternship #WISER #Proxmox #KaliLinux #InformationSecurity #InfoSec #CyberDefense #SecurityMonitoring #ThreatDetection #NetworkMonitoring #UbuntuServer #Linux #MicrosoftTeams #SecurityEngineering #BlueTeam #SOC #CybersecurityProjects #Internship #WISERProgram #WISERExpo #LearningByDoing #ProfessionalDevelopment #KAUST
To view or add a comment, sign in
-