DFIR · OSINT · CTF Writeups

Digging through
memory dumps
and leaving notes.

Field notes from a B.Tech ECE student at NIT Silchar — chasing adversaries through RAM, logs, and open sources. Building toward Threat Intelligence.

06 Writeup
DFIR & Threat Intelligence Primary Focus
Rabbit Holes
wizb@blog ~ whoami
$ cat about.txt
Name : Bornov Shyam Kalita (WizB)
Role : ECE Student · Aspiring DFIR Analyst
Interests : Memory Forensics, OSINT, Malware Analysis
Goal : Threat Intelligence Analyst by end of college

$ ls ./posts/
thm-volatility-case002-wannacry.html
badrabbit-investigation.html
phishstrike-investigation.html
hunter-investigation.html
reveal-investigation.html
hawkeye-investigation.html
... more coming

$
All Posts
HawkEye — The Accountant, The Invoice, and The Keylogger
CyberDefenders Network Forensics Lab. Full PCAP analysis in Wireshark — tracing a phishing invoice download, malware IP reconnaissance, and SMTP credential exfiltration every 10 minutes to an attacker-controlled inbox. Malware identified as HawkEye Keylogger Reborn v9.
Reveal — Hunting StrelaStealer in Memory
CyberDefenders Memory Forensics Lab. Volatility 3 analysis of a financial institution incident — uncovering hidden PowerShell execution, fileless DLL delivery via WebDAV, and StrelaStealer credential theft targeting Thunderbird.
Hunter — The Insider Threat Investigation
CyberDefenders Disk Forensics Lab. Full Windows 8.1 disk image analysis using FTK Imager, Autopsy, and EZ Tools — uncovering port scanning activity, outsider collaboration, data staging, and active anti-forensics via BCWipe.
PhishStrike - From Spoofed Invoice to Multi-Malware Deployment
CyberDefenders Threat Intelligence Lab. Covering MITRE ATT&CK framework mapping, dynamic binary analysis, email header analysis, and threat actor recognition through VirusTotal.
BadRabbit — From Phishing Email to MBR Corruption
CyberDefenders Threat Intelligence Lab. Dynamic malware analysis via ANY.RUN and VirusTotal, MITRE ATT&CK mapping across the full attack chain — from spoofed CEO email to Sandworm attribution and complete disk encryption.
WannaCry in RAM — Dissecting a Ransomware Memory Dump
THM Volatility Case 002. Full memory forensics walkthrough — pslist vs psscan evasion, DLL analysis, mutex IOC extraction, and complete WannaCry attribution from a raw dump.
Network Forensics — Reconstructing an Intrusion from PCAP
Pulling C2 comms, lateral movement, and exfiltration artifacts out of a packet capture. Wireshark deep dive.
// About the Author
WizB

B.Tech ECE student at NIT Silchar, Assam. My interest in cybersecurity started with the psychology behind adversaries — why they do what they do, and how to trace the evidence they leave behind. Focused on DFIR and OSINT, working toward becoming a Threat Intelligence Analyst by end of college.