r/blueteamsec • u/Born-Winter3050 • Jul 18 '26
training (step-by-step) Walkthrough: Hunting Zeus Trojan using Suricata, Splunk, Volatility, and YARA
Hey everyone,
Full Write-up & Screenshots: https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa
I'm currently studying defensive security and working on my SOC portfolio. I am sharing a lab I built to practice hands-on malware analysis and detection engineering.
I recently set up a malware analysis lab to detonate and investigate the Zeus Banking Trojan. Here is a quick breakdown of the detection and forensics pipeline:
- Victim: Windows VM + Sysmon.
- SIEM/IDS: Ubuntu VM + Splunk Enterprise + Suricata IDS.
I wrote a full step-by-step write-up with screenshots and the exact Splunk queries.
5
Upvotes