<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://bit01net.github.io/</id><title>Umamaheswari</title><subtitle>A cybersecurity curiost who always gonna find , break and repair - until i say its over</subtitle> <updated>2026-03-25T17:28:39+00:00</updated> <author> <name>Umamaheswari</name> <uri>https://bit01net.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://bit01net.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://bit01net.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Umamaheswari </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Reaper - LLMNR &amp; NBT-NS Poisoning (PCAP Analysis)</title><link href="https://bit01net.github.io/posts/HTB-Reaper/" rel="alternate" type="text/html" title="Reaper - LLMNR &amp;amp; NBT-NS Poisoning (PCAP Analysis)" /><published>2026-03-25T00:00:00+00:00</published> <updated>2026-03-25T10:38:20+00:00</updated> <id>https://bit01net.github.io/posts/HTB-Reaper/</id> <content type="text/html" src="https://bit01net.github.io/posts/HTB-Reaper/" /> <author> <name>bit01net</name> </author> <category term="Network Traffic" /> <summary>Scenario Our SIEM alerted us to a suspicious logon event which needs to be looked at immediately . The alert details were that the IP Address and the Source Workstation name were a mismatch .You are provided a network capture and event logs from the surrounding time around the incident timeframe. Corelate the given evidence and report back to your SOC Manager. What is LLMNR &amp;amp; NBT-NS LLMNR ...</summary> </entry> <entry><title>Noxious - PCAP Analysis</title><link href="https://bit01net.github.io/posts/HTB-Noxious/" rel="alternate" type="text/html" title="Noxious - PCAP Analysis" /><published>2026-03-25T00:00:00+00:00</published> <updated>2026-03-25T00:00:00+00:00</updated> <id>https://bit01net.github.io/posts/HTB-Noxious/</id> <content type="text/html" src="https://bit01net.github.io/posts/HTB-Noxious/" /> <author> <name>bit01net</name> </author> <category term="Network Traffic" /> <summary>In this lab, we analyze a PCAP to uncover an LLMNR/NBT-NS poisoning attack. Step by step, we identify the rogue machine, trace the victim’s mistake, and observe how credentials were captured and could be used for unauthorized access. This scenario provides a practical view of how such attacks unfold in real environments. Scenario The IDS device alerted us to a possible rogue device in the inte...</summary> </entry> </feed>
