Episode 8 — The Process That Hid in Memory | Security Operations: EDR Detection & Fileless Attacks

Episode 8 — The Process That Hid in Memory | Security Operations: EDR Detection & Fileless Attacks

EPISODE 8 — THE PROCESS THAT HID IN MEMORY Security+ Domain 4 concepts • CySA+ behavioral analytics • SOC fileless attack detection

Modern attackers don’t always drop files. Sometimes the entire attack happens in memory — invisible to antivirus, bypassing traditional scans, and relying on stealth to stay ahead of the SOC.

In this cinematic scenario, you’ll see how defenders detect fileless techniques through subtle signals: unusual PowerShell behavior, reflective loading, credential access attempts, and processes that should never run the way they’re running.

What you’ll learn:

• How fileless attacks operate without touching disk • Why memory-only processes are early indicators of compromise • How EDR/XDR telemetry exposes reflective loading & AMSI bypass attempts • How attackers attempt credential access through LSASS • What suspicious PowerShell behavior looks like • How to isolate, contain, and escalate memory-resident threats

Security Operations Skills Covered:

✔ EDR/XDR telemetry interpretation

✔ Memory analysis fundamentals

✔ Fileless malware techniques

✔ Behavioral & heuristic detection

✔ Credential theft monitoring

✔ Threat hunting signals

✔ Incident response workflow for in-memory attacks

This scenario reinforces key concepts from:

Security+ (SY0-701) — EDR/XDR, behavioral detection, malware identification, IR workflows

CySA+ (CS0-003) — Memory-based attacks, credential access attempts, advanced detection analytics

Designed to support both exam learners and working SOC analysts.


Ideal for:

— Security+ learners — CySA+ learners — SOC Tier 1 analysts — Blue team defenders — Incident responders — Anyone learning how modern attackers avoid traditional AV

Short. Cinematic. Practical. A real-world look into attacks designed to stay invisible.

New episodes weekly.


Explore the works of M.G. Vance on Amazon — including Security+, CySA+, CISA, CISM, CRISC, and The Breach Nobody Saw Coming titles.

Amazon Author Page: https://www.amazon.com/stores/author/B0FX7TZSV4/

CyberLex Learning — Forge the Defender.

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(22)

Episode 10 — The Scheduled Task That Recreated Itself | Security Operations: Persistence & Automated Rebuild Loops

Episode 10 — The Scheduled Task That Recreated Itself | Security Operations: Persistence & Automated Rebuild Loops

EPISODE 10 — THE SCHEDULED TASK THAT RECREATED ITSELF Security+ Domain 4 concepts • CySA+ threat analytics • SOC persistence detectionPersistence is the attacker’s greatest weapon. And one of the stea...

2 Jan 3min

Episode 9 — The DNS Query That Didn’t Match Any Pattern | Security Operations: DNS Analysis & C2 Detection

Episode 9 — The DNS Query That Didn’t Match Any Pattern | Security Operations: DNS Analysis & C2 Detection

EPISODE 9 — THE DNS QUERY THAT DIDN’T MATCH ANY PATTERN Security+ Domain 4 concepts • CySA+ network analytics • SOC DNS anomaly detectionDNS is one of the most misunderstood — and most exploited — pro...

26 Des 20253min

Episode 7 — The Cloud Bucket Created at 3:14 A.M. | Security Operations: Cloud Monitoring & Rogue Resource Detection

Episode 7 — The Cloud Bucket Created at 3:14 A.M. | Security Operations: Cloud Monitoring & Rogue Resource Detection

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 7 — THE CLOUD BUCKET CREATED AT 3:14 A.M. Security+ Domain 4 concepts • CySA+ cloud analytics • SOC cloud misconfiguration detectionClou...

14 Des 20253min

Episode 6 — The Email That Passed Every Check | Security Operations: Email Threat Detection & Identity Attacks

Episode 6 — The Email That Passed Every Check | Security Operations: Email Threat Detection & Identity Attacks

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 6 — THE EMAIL THAT PASSED EVERY CHECK Security+ Domain 4 concepts • CySA+ email threat analytics • SOC identity attack detectionSome of ...

13 Des 20253min

Episode 5 — The Firewall Rule That Quietly Opened | Security Operations: Enterprise Controls & Outbound Anomalies

Episode 5 — The Firewall Rule That Quietly Opened | Security Operations: Enterprise Controls & Outbound Anomalies

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 5 — THE FIREWALL RULE THAT QUIETLY OPENED Security+ Domain 4 concepts • CySA+ network analytics • SOC enterprise control monitoringSome ...

12 Des 20253min

Episode 4 — The Login That Didn’t Belong to the User | Security Operations: IAM Anomalies & Behavioral Detection

Episode 4 — The Login That Didn’t Belong to the User | Security Operations: IAM Anomalies & Behavioral Detection

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 4 — THE LOGIN THAT DIDN’T BELONG TO THE USER Security+ Domain 4 concepts • CySA+ authentication analytics • SOC identity anomaly detecti...

11 Des 20253min

Episode 3 — The Vulnerability That Came Back | Security Operations: Vulnerability Lifecycle & Configuration Drift

Episode 3 — The Vulnerability That Came Back | Security Operations: Vulnerability Lifecycle & Configuration Drift

CyberLex Blue Team Academy — Where Defenders Are Forged.EPISODE 3 — THE VULNERABILITY THAT CAME BACK Security+ Domain 4 concepts • CySA+ vulnerability analytics • SOC lifecycle investigationIn Securit...

10 Des 20253min

Populært innen Teknologi

teknisk-sett
tomprat-med-gunnar-tjomlid
lydartikler-fra-aftenposten
energi-og-klima
elektropodden
rss-ki-praten
hans-petter-og-co
nasjonal-sikkerhetsmyndighet-nsm
shifter
smart-forklart
rss-alt-som-gar-pa-strom
rss-ai-forklart
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
fornybaren
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis