Investigations

Building a Tier 1 SOC Dashboard in Splunk

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Investigating Suspicious PowerShell Activity with Splunk

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

6 Real Problems I Solved While Building My SOC Homelab

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology