root@z2r:~/blog/tags#grep -r "TryHackMe" ./posts
<Tag: TryHackMe />
Found 2 posts with this tag.
CTF WRITEUPSFORENSICS
THM - After Hours
A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.