Building a Tier 1 SOC Dashboard in Splunk
Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility
Exploring cybersecurity incidents through structured SOC investigations.
Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility
Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment
Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
A Complete Write-Up Demonstrating Real SOC Investigation Methodology
Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation
A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.
Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration
Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques
Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset
Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset
Complete writeup with binary analysis, string decoding, and DFIR techniques