> For the complete documentation index, see [llms.txt](https://aj-read.gitbook.io/writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://aj-read.gitbook.io/writeups/blueteamlabs-investigations/readme.md).

# README

Writeups for [Blue Team Labs Investigations](https://blueteamlabs.online/home/investigations).

## Medium

### SAM

* Writeup [here](https://github.com/ajread4/BTL-Investigations/blob/main/Sam.md)
* Medium level difficulty
* Use of sysmon to find initial access, powershell for post exploitation actions
* Packet capture involved in beaconing
* Volatility utilized to analyze SAM and SYSTEM hive

### Pretium

* Writeup [here](/writeups/blueteamlabs-investigations/pretium.md)
* Medium level difficulty
* Interesting beaconing detection using ICMP
* Big focus on pcap and tshark capability
