Skip to main content
  1. Policy to Packets/
  2. Tags/

Talos_Intelligence

(Writeup) LetsDefend EventID: 118 - [SOC168 - Whoami Command Detected in Request Body]

Investigating a command injection alert after POST requests containing system commands targeted a web endpoint, validating attacker IP reputation and analyzing HTTP response behavior, confirming successful command execution through response size variation, and initiating containment and escalation due to a confirmed web shell.

(Writeup) LetsDefend EventID: 115 - [SOC165 - Possible SQL Injection Payload Detected]

Investigating a SQL injection alert after repeated crafted payloads targeted a web server, decoding and validating the requests through log analysis, reviewing source IP reputation across multiple threat intelligence sources, and confirming the attack was unsuccessful based on server responses and endpoint verification.