<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>JD Security — Blog</title><link>https://jamaldarbo.nl/blog/</link><description>Technical notes, security investigations and lessons learned by Jamal Darbo.</description><language>en-gb</language><atom:link href="https://jamaldarbo.nl/rss.xml" rel="self" type="application/rss+xml"/><item><title>Under the hood of Windows: Using Process Monitor</title><link>https://jamaldarbo.nl/blog/under-the-hood-of-windows-using-process-monitor/</link><guid isPermaLink="true">https://jamaldarbo.nl/blog/under-the-hood-of-windows-using-process-monitor/</guid><description>A step-by-step look at svchost.exe with Process Monitor: filtering events, following file and registry activity, and understanding the parent process.</description><pubDate>Fri, 23 May 2025 00:00:00 GMT</pubDate><category>Windows Security</category><category>Process Monitor</category><category>Sysinternals</category></item><item><title>Packet capture analysis of a SocGholish and AsyncRAT infection</title><link>https://jamaldarbo.nl/blog/packet-capture-analysis-of-a-socgholish-and-asyncrat-infection/</link><guid isPermaLink="true">https://jamaldarbo.nl/blog/packet-capture-analysis-of-a-socgholish-and-asyncrat-infection/</guid><description>Following a SocGholish and AsyncRAT infection through a packet capture: suspicious TLS traffic, DNS correlations, HTTP streams and obfuscated PowerShell.</description><pubDate>Thu, 15 May 2025 00:00:00 GMT</pubDate><category>Malware Analysis</category><category>Wireshark</category><category>Network Analysis</category></item><item><title>Investigating Koi Stealer malware using Wireshark</title><link>https://jamaldarbo.nl/blog/investigating-koi-stealer-malware-using-wireshark/</link><guid isPermaLink="true">https://jamaldarbo.nl/blog/investigating-koi-stealer-malware-using-wireshark/</guid><description>An end-to-end Wireshark investigation of a Koi Stealer packet capture, examining beaconing, HTTP payloads, internal network activity and indicators of compromise.</description><pubDate>Tue, 15 Apr 2025 00:00:00 GMT</pubDate><category>Malware Analysis</category><category>Wireshark</category><category>Network Analysis</category></item></channel></rss>
