Tag: Threat Hunting

Tor and Anonymizer Egress Hunting on VPC Flow Logs — Exit-node enrichment and multi-hop circuit analysis
0 20
Posted in Cyber Threat

Tor and Anonymizer Egress Hunting on VPC Flow Logs

Tor egress | anonymizer | VPN | proxy | exit node | VPC Flow Logs

Cloud Cryptojacking Detection at Scale — Mining pool fingerprinting and sustained-traffic ML on AWS VPC Flow Logs
0 18
Posted in Cyber Threat

Cloud Cryptojacking Detection at Scale: Mining-Pool Hunting on AWS

Cryptojacking detection | XMRig | Monero | Stratum | mining pool | AWS VPC

TLS Fingerprinting for Encrypted C2 Hunting — JA3, JA4, JARM analysis on AWS VPC Flow Logs
0 17
Posted in Cyber Threat

TLS Fingerprinting (JA3, JA4, JARM) for Encrypted C2 Hunting

TLS fingerprinting | JA3 | JA4 | JARM | encrypted C2 | VPC Flow Logs

DGA and DNS-Tunnel Hunting at Scale — ML domain anomaly and tunnel volumetrics on VPC Flow Logs
0 22
Posted in Cyber Threat

DGA and DNS-Tunnel Hunting at Scale on VPC Flow Logs

DGA detection | DNS tunnel | NXDOMAIN | entropy | iodine | VPC Flow Logs

Lateral Movement Graph Detection — GNN + PageRank on internal VPC Flow Logs — HACKFORLAB cover image
0 23
Posted in Cyber Threat

Lateral Movement Detection via Graph Analysis on VPC Flow Logs

Detect multi-hop lateral movement (SMB, WinRM, RDP, SSH) with GNN, PageRank, and Louvain community detection on AWS VPC Flow Logs.