Skip to content

OsmanDhaqane/boogeyman-2-tryhackme-writeup

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

This repository contains my write-up for the TryHackMe room Boogeyman 2.

The room focuses on investigating a phishing attack where a malicious resume document compromised a victim workstation. The analysis covers email header review, attachment extraction, macro analysis with olevba, memory forensics with Volatility, C2 connection investigation, and scheduled task persistence.

Skills Practiced

  • Phishing email analysis
  • Malicious attachment investigation
  • Base64 attachment extraction from .eml files
  • VBA macro analysis with olevba
  • Memory forensics with Volatility
  • Process and command-line analysis
  • C2 network connection identification
  • Scheduled task persistence detection

Tools Used

  • Pluma
  • Python
  • md5sum
  • olevba
  • Volatility
  • strings
  • grep

Walkthrough

The full walkthrough is available here:

boogeyman-2-tryhackme-writeup.pdf

About

TryHackMe Boogeyman 2 write-up covering phishing email analysis, malicious document macros, memory forensics, C2 investigation, and persistence detection.

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors