Field Notes

Case notes and artifacts

Short, indexable notes from investigations: telemetry, odd artifacts, tradecraft observations, and quick pivots that do not need a full blog post.

  1. Edge Device investigation Internal Files

    Exploring SonicWall techSupport Exports

    An overview of the forensic value contained within SonicWall techSupport packages, from authentication configuration to audit history and identity data.

    • Observed
    • SonicWall SSLVPN
    • SonicWall VirtualOffice
    • LDAP
    • SAML

    #sslvpn#dfir#sonicwall

  2. Endpoint investigation Process, network, and file telemetry

    Hunting Anomalous Python Execution

    A renamed Dropbox updater, a year-old staging link, and a prayer; surfacing CobaltStrike one hypothesis at a time.

    • Observed
    • CobaltStrike
    • Renamed PythonW
    • Sideloading python310.dll

    #cobaltstrike#sideloading#dfir#c2

  3. Endpoint investigation Process, network, and file telemetry

    Nezha RMM and a suspicious vmtools.exe SOCKS5 proxy

    A short investigation note on a host where Nezha Chinese RMM led to a mislabeled Node runtime, SOCKS5 proxy payload, and PowerShell collection script.

    • Observed
    • Nezha RMM
    • Fake Windows Spooler service
    • Mislabeled vmtools.exe Node runtime
    • SOCKS5 proxy payload

    #nezha#rmm#socks5#dfir#c2