CITADEL CYBERSEC

CITADEL CYBERSEC

Exploring cybersecurity incidents through structured SOC investigations.

Building a Tier 1 SOC Dashboard in Splunk

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

in
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

in
Investigating Suspicious PowerShell Activity with Splunk

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

in
6 Real Problems I Solved While Building My SOC Homelab

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

in
SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

in
SOC Alert: Conti Ransomware Investigation

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

in
Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

in
Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

in
Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

in
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

in
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

in
TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

Complete writeup with binary analysis, string decoding, and DFIR techniques

in
Building a Tier 1 SOC Dashboard in Splunk

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

in
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

in
Investigating Suspicious PowerShell Activity with Splunk

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

in
6 Real Problems I Solved While Building My SOC Homelab

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

in
SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

in