From Splunk to Sigma: Building and Validating Vendor-Neutral Detection Logic
A detection-engineering exercise using Sigma, Splunk, Windows telemetry, and Atomic Red Team to validate vendor-neutral detection logic
Exploring cybersecurity incidents through structured SOC investigations.
A detection-engineering exercise using Sigma, Splunk, Windows telemetry, and Atomic Red Team to validate vendor-neutral detection logic
How to Validate PowerShell Detections in Splunk with Sysmon, Atomic Red Team, and MITRE ATT&CK
Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility
Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment
Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
A Complete Write-Up Demonstrating Real SOC Investigation Methodology
Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation
A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.
Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration
Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques
Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset
Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset
Complete writeup with binary analysis, string decoding, and DFIR techniques