Tag: VPC Flow Logs

TLS Fingerprinting for Encrypted C2 Hunting — JA3, JA4, JARM analysis on AWS VPC Flow Logs
0 18
Posted in Cyber Threat

TLS Fingerprinting (JA3, JA4, JARM) for Encrypted C2 Hunting

TLS fingerprinting | JA3 | JA4 | JARM | encrypted C2 | VPC Flow Logs

DGA and DNS-Tunnel Hunting at Scale — ML domain anomaly and tunnel volumetrics on VPC Flow Logs
0 23
Posted in Cyber Threat

DGA and DNS-Tunnel Hunting at Scale on VPC Flow Logs

DGA detection | DNS tunnel | NXDOMAIN | entropy | iodine | VPC Flow Logs

Lateral Movement Graph Detection — GNN + PageRank on internal VPC Flow Logs — HACKFORLAB cover image
0 24
Posted in Cyber Threat

Lateral Movement Detection via Graph Analysis on VPC Flow Logs

Detect multi-hop lateral movement (SMB, WinRM, RDP, SSH) with GNN, PageRank, and Louvain community detection on AWS VPC Flow Logs.

Low-and-Slow Data Exfiltration Detection — Isolation Forest + LSTM autoencoder on VPC Flow Logs — HACKFORLAB cover image
0 21
Posted in Cyber Threat

Detecting Low-and-Slow Data Exfiltration with Isolation Forest + LSTM

Hunt DNS tunnels, ICMP tunnels, and HTTPS covert channels using Isolation Forest + LSTM autoencoder on AWS VPC Flow Logs.

Botnet Coordination & DDoS Staging Hunt — K-means + hierarchical clustering on VPC Flow Logs — HACKFORLAB cover image
0 21
Posted in Cyber Threat

Hunting Botnet Coordination and DDoS Staging with Clustering

Surface coordinated botnets and pre-DDoS staging via K-means + hierarchical clustering on host behaviour fingerprints from AWS VPC Flow Logs.