root@thehacksparrow:~/writeups$ SYSTEM ONLINE
root@sparrow:~/writeups$ cat invite-only.md
// Blue Team & SOC

Invite Only

19 Aug 2024 · 11 min read · user access
In Invite Only you play a SOC analyst at the Managed Server Provider TrySecureMe. An L1 analyst escalates two suspicious indicators —an IP address and a SHA256 hash— and your mission is to pivot on them using the in-house threat intelligence tool TryDetectThis2.0, reconstruct the attack chain, and extract actionable intelligence. The case blends file analysis, malware-family identification, and OSINT research into a single investigation.
PlatformTryHackMe
CategoryBlue Team & SOC — Threat Intelligence
DifficultyEasy
RoomInvite Only

Pivot map

[IP + SHA256] --> TryDetectThis2.0
      |
      v
syshelpers.exe (Win32 EXE)
      |
      v  parents (chronological)
361GJX7J --> installer.exe
      |                    |
      v drops              v drops
Aclient.exe          searchhost.exe, syshelpers.exe, nat.vbs, runsys.vbs
      |
      v  correlate across all IOCs
AsyncRAT (malware family)
      |
      v  OSINT
Check Point report: "From Trust to Threat..."
      |
      v  TTPs confirmed
ClickFix (delivery) + hijacked Discord invites (redirection) + ChromeKatz (cookie theft)
🔒 Free account required

This is USER ACCESS content — free to unlock, no payment. The rest of the write-up (and everything else at this level) opens up once you're signed in.

Create a free account