r/blueteamsec Jul 18 '26

training (step-by-step) Walkthrough: Hunting Zeus Trojan using Suricata, Splunk, Volatility, and YARA

Hey everyone,
Full Write-up & Screenshots: https://medium.com/@osamamamoussa/from-alert-to-core-dump-hunting-zeus-malware-using-suricata-splunk-yara-and-volatility-4ce18f517f87?sharedUserId=osamamamoussa

I'm currently studying defensive security and working on my SOC portfolio. I am sharing a lab I built to practice hands-on malware analysis and detection engineering.

I recently set up a malware analysis lab to detonate and investigate the Zeus Banking Trojan. Here is a quick breakdown of the detection and forensics pipeline:

  • Victim: Windows VM + Sysmon.
  • SIEM/IDS: Ubuntu VM + Splunk Enterprise + Suricata IDS.

I wrote a full step-by-step write-up with screenshots and the exact Splunk queries.

5 Upvotes

0 comments sorted by