Citadel Cybersec

Menu

  • Home
  • Investigations
  • Certifications
  • About Me
  • Contact
  • Home
  • Investigations
  • Certifications
  • About Me
  • Contact
Search
2 posts tagged

active-directory

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
1 post tagged

allowlist

Efficient Algorithm for Allow List File Updates in Python
3 min read Oct 13, 2025

Efficient Algorithm for Allow List File Updates in Python

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in python allowlist programming
1 post tagged

aws

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
12 min read May 5, 2026

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

Raúl Vázquez González's Picture
Raúl Vázquez González in ransomware threat-hunting splunk tryhackme aws
1 post tagged

azure-security

Cloud-based Threat Detection with Splunk
4 min read Nov 26, 2025

Cloud-based Threat Detection with Splunk

Solving Rotten Cloud Investigation — Blue Team Labs Online (Halloween 2025 Special Event)

Raúl Vázquez González's Picture
Raúl Vázquez González in cloud-security splunk azure-security btlo
16 posts tagged

blue-team

6 Real Problems I Solved While Building My SOC Homelab
10 min read Jun 17, 2026

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team networking
SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
6 min read Jun 4, 2026

I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?

Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk
CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals
8 min read May 26, 2026

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals

A hands-on path into modern blue team operations

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst blue-team dfir siem certifications
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)
8 min read Mar 27, 2026

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)
9 min read Mar 20, 2026

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules
2 min read Feb 12, 2026

Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules

Identifying cleartext credentials inside packet captures and generating actionable firewall rules

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security blue-team tryhackme
How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide
8 min read Jan 26, 2026

How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide

A breakdown of the SAL1 exam, its SOC scenarios, tools, and how to prepare effectively using TryHackMe

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
Detecting Web Shells in WordPress Through Apache Log Analysis
3 min read Jan 21, 2026

Detecting Web Shells in WordPress Through Apache Log Analysis

A TryHackMe writeup from the “Detecting Web Shells” room — Task 6 Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in web-security incident-response blue-team tryhackme
Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
8 min read Jan 7, 2026

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell

TryHackMe Sysmon Task 10 - Practical Investigations Explained (With PowerShell)

Raúl Vázquez González's Picture
Raúl Vázquez González in sysmon incident-response powershell blue-team tryhackme
Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis
3 min read Dec 22, 2025

Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis

ICMP and DNS exfiltration techniques and malicious cleartext FTP behavior

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security threat-detection blue-team
Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs
4 min read Dec 10, 2025

Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs

TryHackMe — Network Security Essentials (Task 7 Practical Exercise)

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem network-security blue-team
The new TryHackMe SOC Level 1 Path
7 min read Nov 10, 2025

The new TryHackMe SOC Level 1 Path

Now getting ready for the job got even better

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
My Experience with the Blue Team Level 1 (BTL1) Certification
4 min read Oct 16, 2025

My Experience with the Blue Team Level 1 (BTL1) Certification

A Broad and Professional Blue-Team Skillset

Raúl Vázquez González's Picture
Raúl Vázquez González in blue-team certifications incident-response digital-forensics threat-hunting
Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef
5 min read Oct 13, 2025

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef

A detailed writeup of TryHackMe’s “Investigating with Splunk” final question

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk cyberchef powershell blue-team tryhackme
1 post tagged

bluetooth

Why You Should Disable Bluetooth on Linux (and How to Do It)
4 min read Sep 11, 2025

Why You Should Disable Bluetooth on Linux (and How to Do It)

All the Ways to Disable Bluetooth for Good

Raúl Vázquez González's Picture
Raúl Vázquez González in bluetooth linux-security linux-hardening
1 post tagged

books

What Future Crimes Taught Me About Cybersecurity
3 min read Apr 15, 2026

What Future Crimes Taught Me About Cybersecurity

Context is the key to understanding modern cyber threats

Raúl Vázquez González's Picture
Raúl Vázquez González in infosec cyber-security-awareness cybercrime cybersecurity books
1 post tagged

brim

Searching, Filtering, and Correlation: Threat Hunting with Brim
4 min read Dec 4, 2025

Searching, Filtering, and Correlation: Threat Hunting with Brim

Using Brim capabilities to identify malicious activities

Raúl Vázquez González's Picture
Raúl Vázquez González in brim threat-hunting network-analysis tryhackme
1 post tagged

btlo

Cloud-based Threat Detection with Splunk
4 min read Nov 26, 2025

Cloud-based Threat Detection with Splunk

Solving Rotten Cloud Investigation — Blue Team Labs Online (Halloween 2025 Special Event)

Raúl Vázquez González's Picture
Raúl Vázquez González in cloud-security splunk azure-security btlo
1 post tagged

certification

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice
9 min read Feb 25, 2026

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk certification spl dashboards
5 posts tagged

certifications

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals
8 min read May 26, 2026

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals

A hands-on path into modern blue team operations

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst blue-team dfir siem certifications
How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide
8 min read Jan 26, 2026

How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide

A breakdown of the SAL1 exam, its SOC scenarios, tools, and how to prepare effectively using TryHackMe

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
The new TryHackMe SOC Level 1 Path
7 min read Nov 10, 2025

The new TryHackMe SOC Level 1 Path

Now getting ready for the job got even better

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
My Experience with the Blue Team Level 1 (BTL1) Certification
4 min read Oct 16, 2025

My Experience with the Blue Team Level 1 (BTL1) Certification

A Broad and Professional Blue-Team Skillset

Raúl Vázquez González's Picture
Raúl Vázquez González in blue-team certifications incident-response digital-forensics threat-hunting
What’s Next After CompTIA Security+? My Experience with the Google Cybersecurity Certificate
3 min read Aug 25, 2025

What’s Next After CompTIA Security+? My Experience with the Google Cybersecurity Certificate

Excellent cybersecurity fundamentals with practical assignments

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications
1 post tagged

chmod

Managing File Permissions in Linux Using chmod
3 min read Sep 15, 2025

Managing File Permissions in Linux Using chmod

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in chmod linux-security linux-hardening file-permissions
1 post tagged

cloud-security

Cloud-based Threat Detection with Splunk
4 min read Nov 26, 2025

Cloud-based Threat Detection with Splunk

Solving Rotten Cloud Investigation — Blue Team Labs Online (Halloween 2025 Special Event)

Raúl Vázquez González's Picture
Raúl Vázquez González in cloud-security splunk azure-security btlo
1 post tagged

compliance

Conducting a Security Audit
3 min read Sep 4, 2025

Conducting a Security Audit

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in security-audit compliance data-protection
1 post tagged

cyber-security-awareness

What Future Crimes Taught Me About Cybersecurity
3 min read Apr 15, 2026

What Future Crimes Taught Me About Cybersecurity

Context is the key to understanding modern cyber threats

Raúl Vázquez González's Picture
Raúl Vázquez González in infosec cyber-security-awareness cybercrime cybersecurity books
1 post tagged

cyberchef

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef
5 min read Oct 13, 2025

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef

A detailed writeup of TryHackMe’s “Investigating with Splunk” final question

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk cyberchef powershell blue-team tryhackme
1 post tagged

cybercrime

What Future Crimes Taught Me About Cybersecurity
3 min read Apr 15, 2026

What Future Crimes Taught Me About Cybersecurity

Context is the key to understanding modern cyber threats

Raúl Vázquez González's Picture
Raúl Vázquez González in infosec cyber-security-awareness cybercrime cybersecurity books
1 post tagged

cybersecurity

What Future Crimes Taught Me About Cybersecurity
3 min read Apr 15, 2026

What Future Crimes Taught Me About Cybersecurity

Context is the key to understanding modern cyber threats

Raúl Vázquez González's Picture
Raúl Vázquez González in infosec cyber-security-awareness cybercrime cybersecurity books
6 posts tagged

cybersecurity-lab

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Suspicious PowerShell Activity with Splunk
9 min read Jun 23, 2026

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk powershell
6 Real Problems I Solved While Building My SOC Homelab
10 min read Jun 17, 2026

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team networking
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
6 min read Jun 4, 2026

I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?

Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk
1 post tagged

dashboards

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice
9 min read Feb 25, 2026

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk certification spl dashboards
1 post tagged

data-filtering

Apply Filters to SQL Queries: A Cybersecurity Use Case
3 min read Sep 22, 2025

Apply Filters to SQL Queries: A Cybersecurity Use Case

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in sql data-filtering threat-hunting
1 post tagged

data-protection

Conducting a Security Audit
3 min read Sep 4, 2025

Conducting a Security Audit

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in security-audit compliance data-protection
1 post tagged

ddos

Leveraging Splunk SIEM to Detect DoS Attacks
3 min read Dec 24, 2025

Leveraging Splunk SIEM to Detect DoS Attacks

TryHackMe Detecting Web DDoS Room, Task 5 Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk ddos web-security tryhackme
2 posts tagged

detection-engineering

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
4 posts tagged

dfir

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals
8 min read May 26, 2026

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals

A hands-on path into modern blue team operations

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst blue-team dfir siem certifications
Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2
10 min read May 13, 2026

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

Raúl Vázquez González's Picture
Raúl Vázquez González in dfir phishing malware-analysis volatility
TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction
3 min read Feb 2, 2026

TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

Complete writeup with binary analysis, string decoding, and DFIR techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in malware-analysis dfir incident-response tryhackme
Windows Forensics: How I Traced Suspicious Activity Using Registry Hives
3 min read Nov 10, 2025

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives

Using Eric Zimmerman’s Registry Explorer to locate key forensic artifacts

Raúl Vázquez González's Picture
Raúl Vázquez González in ez-tools digital-forensics windows-forensics dfir
1 post tagged

dfir tryhackme

Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs
3 min read Nov 21, 2025

Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs

TryHackMe Snapped Phish-ing Line Room Write‑Up

Raúl Vázquez González's Picture
Raúl Vázquez González in phishing incident-response dfir tryhackme
3 posts tagged

digital-forensics

Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos
1 min read Dec 10, 2025

Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos

Practical examples of how to use Wireshark to answer specific questions about network activity

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis digital-forensics
Windows Forensics: How I Traced Suspicious Activity Using Registry Hives
3 min read Nov 10, 2025

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives

Using Eric Zimmerman’s Registry Explorer to locate key forensic artifacts

Raúl Vázquez González's Picture
Raúl Vázquez González in ez-tools digital-forensics windows-forensics dfir
My Experience with the Blue Team Level 1 (BTL1) Certification
4 min read Oct 16, 2025

My Experience with the Blue Team Level 1 (BTL1) Certification

A Broad and Professional Blue-Team Skillset

Raúl Vázquez González's Picture
Raúl Vázquez González in blue-team certifications incident-response digital-forensics threat-hunting
1 post tagged

elastic

Elastic Stack (ELK) for SOC Log Investigations
4 min read Feb 16, 2026

Elastic Stack (ELK) for SOC Log Investigations

Essential ELK techniques for investigating and querying logs

Raúl Vázquez González's Picture
Raúl Vázquez González in elk elastic elastic-search elastic-stack tryhackme
1 post tagged

elastic-search

Elastic Stack (ELK) for SOC Log Investigations
4 min read Feb 16, 2026

Elastic Stack (ELK) for SOC Log Investigations

Essential ELK techniques for investigating and querying logs

Raúl Vázquez González's Picture
Raúl Vázquez González in elk elastic elastic-search elastic-stack tryhackme
1 post tagged

elastic-stack

Elastic Stack (ELK) for SOC Log Investigations
4 min read Feb 16, 2026

Elastic Stack (ELK) for SOC Log Investigations

Essential ELK techniques for investigating and querying logs

Raúl Vázquez González's Picture
Raúl Vázquez González in elk elastic elastic-search elastic-stack tryhackme
1 post tagged

elk

Elastic Stack (ELK) for SOC Log Investigations
4 min read Feb 16, 2026

Elastic Stack (ELK) for SOC Log Investigations

Essential ELK techniques for investigating and querying logs

Raúl Vázquez González's Picture
Raúl Vázquez González in elk elastic elastic-search elastic-stack tryhackme
1 post tagged

ez-tools

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives
3 min read Nov 10, 2025

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives

Using Eric Zimmerman’s Registry Explorer to locate key forensic artifacts

Raúl Vázquez González's Picture
Raúl Vázquez González in ez-tools digital-forensics windows-forensics dfir
1 post tagged

file-permissions

Managing File Permissions in Linux Using chmod
3 min read Sep 15, 2025

Managing File Permissions in Linux Using chmod

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in chmod linux-security linux-hardening file-permissions
1 post tagged

firewall

Linux Workstation Hardening: Enhancing Security with UFW
7 min read Oct 2, 2025

Linux Workstation Hardening: Enhancing Security with UFW

Master UFW and Kernel Hardening to Fortify Your Linux Workstation Against Threats

Raúl Vázquez González's Picture
Raúl Vázquez González in ufw linux-security linux-hardening firewall
6 posts tagged

homelab

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Suspicious PowerShell Activity with Splunk
9 min read Jun 23, 2026

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk powershell
6 Real Problems I Solved While Building My SOC Homelab
10 min read Jun 17, 2026

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team networking
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
6 min read Jun 4, 2026

I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?

Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk
9 posts tagged

incident-response

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
SOC Alert: Conti Ransomware Investigation
18 min read May 21, 2026

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in soc splunk ransomware incident-response threat-hunting
Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
7 min read Apr 27, 2026

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in network-security network-forensics incident-response wireshark log-analysis
Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
9 min read Apr 13, 2026

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst incident-response threat-hunting xdr tryhackme
TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction
3 min read Feb 2, 2026

TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

Complete writeup with binary analysis, string decoding, and DFIR techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in malware-analysis dfir incident-response tryhackme
Detecting Web Shells in WordPress Through Apache Log Analysis
3 min read Jan 21, 2026

Detecting Web Shells in WordPress Through Apache Log Analysis

A TryHackMe writeup from the “Detecting Web Shells” room — Task 6 Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in web-security incident-response blue-team tryhackme
Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
8 min read Jan 7, 2026

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell

TryHackMe Sysmon Task 10 - Practical Investigations Explained (With PowerShell)

Raúl Vázquez González's Picture
Raúl Vázquez González in sysmon incident-response powershell blue-team tryhackme
Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs
3 min read Nov 21, 2025

Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs

TryHackMe Snapped Phish-ing Line Room Write‑Up

Raúl Vázquez González's Picture
Raúl Vázquez González in phishing incident-response dfir tryhackme
My Experience with the Blue Team Level 1 (BTL1) Certification
4 min read Oct 16, 2025

My Experience with the Blue Team Level 1 (BTL1) Certification

A Broad and Professional Blue-Team Skillset

Raúl Vázquez González's Picture
Raúl Vázquez González in blue-team certifications incident-response digital-forensics threat-hunting
1 post tagged

infosec

What Future Crimes Taught Me About Cybersecurity
3 min read Apr 15, 2026

What Future Crimes Taught Me About Cybersecurity

Context is the key to understanding modern cyber threats

Raúl Vázquez González's Picture
Raúl Vázquez González in infosec cyber-security-awareness cybercrime cybersecurity books
4 posts tagged

intrusion-detection

Regular Expressions
3 min read Feb 23, 2026

Regular Expressions

A TryHackMe Regex Practical Exercise Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in regex intrusion-detection tryhackme
Mastering Snort: Stopping Real-Time Attacks
3 min read Nov 10, 2025

Mastering Snort: Stopping Real-Time Attacks

Learn how to detect and block brute-force and reverse shell attacks using Snort IDS/IPS

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts
4 min read Nov 8, 2025

Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts

Fine-tune Snort rules for effective packet analysis

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Snort Challenge: The Basics Writeup
23 min read Nov 8, 2025

Snort Challenge: The Basics Writeup

A hands-on walkthrough covering Snort IDS rule creation, traffic analysis, signature-based detection and troubleshooting

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
2 posts tagged

kerberos

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
3 posts tagged

linux-hardening

Linux Workstation Hardening: Enhancing Security with UFW
7 min read Oct 2, 2025

Linux Workstation Hardening: Enhancing Security with UFW

Master UFW and Kernel Hardening to Fortify Your Linux Workstation Against Threats

Raúl Vázquez González's Picture
Raúl Vázquez González in ufw linux-security linux-hardening firewall
Managing File Permissions in Linux Using chmod
3 min read Sep 15, 2025

Managing File Permissions in Linux Using chmod

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in chmod linux-security linux-hardening file-permissions
Why You Should Disable Bluetooth on Linux (and How to Do It)
4 min read Sep 11, 2025

Why You Should Disable Bluetooth on Linux (and How to Do It)

All the Ways to Disable Bluetooth for Good

Raúl Vázquez González's Picture
Raúl Vázquez González in bluetooth linux-security linux-hardening
3 posts tagged

linux-security

Linux Workstation Hardening: Enhancing Security with UFW
7 min read Oct 2, 2025

Linux Workstation Hardening: Enhancing Security with UFW

Master UFW and Kernel Hardening to Fortify Your Linux Workstation Against Threats

Raúl Vázquez González's Picture
Raúl Vázquez González in ufw linux-security linux-hardening firewall
Managing File Permissions in Linux Using chmod
3 min read Sep 15, 2025

Managing File Permissions in Linux Using chmod

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in chmod linux-security linux-hardening file-permissions
Why You Should Disable Bluetooth on Linux (and How to Do It)
4 min read Sep 11, 2025

Why You Should Disable Bluetooth on Linux (and How to Do It)

All the Ways to Disable Bluetooth for Good

Raúl Vázquez González's Picture
Raúl Vázquez González in bluetooth linux-security linux-hardening
1 post tagged

log-analysis

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
7 min read Apr 27, 2026

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in network-security network-forensics incident-response wireshark log-analysis
3 posts tagged

malware-analysis

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2
10 min read May 13, 2026

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

Raúl Vázquez González's Picture
Raúl Vázquez González in dfir phishing malware-analysis volatility
Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup
3 min read Mar 5, 2026

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup

A practical SOC analyst investigation of malicious hashes, phishing techniques, and malware delivery chains from the Invite Only TryHackMe room

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst malware-analysis threat-intelligence virustotal tryhackme
TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction
3 min read Feb 2, 2026

TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

Complete writeup with binary analysis, string decoding, and DFIR techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in malware-analysis dfir incident-response tryhackme
1 post tagged

mitm

Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle
2 min read Dec 2, 2025

Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle

Analyzing network traffic to identify ARP requests, HTTP packets, and sniffed login credentials

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis mitm
1 post tagged

mitre

USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise
3 min read Sep 15, 2025

USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise

Identifying Tactics, Techniques and Procedures of an APT

Raúl Vázquez González's Picture
Raúl Vázquez González in threat-intelligence mitre opencti
1 post tagged

mitre-attck

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
3 posts tagged

network-analysis

Wireshark Traffic Analysis: A Comprehensive Guide
1 min read Feb 27, 2026

Wireshark Traffic Analysis: A Comprehensive Guide

A Complete Guide to Solving TryHackMe’s Wireshark Traffic Analysis Room - A Step-by-Step Walkthrough of All Tasks and Insights

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis packet-analysis network-forensics tryhackme
Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis
2 min read Dec 30, 2025

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis

Anomalous user agents, subtle anomalies in packet data and specific attack patterns

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis network-security pcap-analysis tryhackme
Searching, Filtering, and Correlation: Threat Hunting with Brim
4 min read Dec 4, 2025

Searching, Filtering, and Correlation: Threat Hunting with Brim

Using Brim capabilities to identify malicious activities

Raúl Vázquez González's Picture
Raúl Vázquez González in brim threat-hunting network-analysis tryhackme
3 posts tagged

network-forensics

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
7 min read Apr 27, 2026

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in network-security network-forensics incident-response wireshark log-analysis
Wireshark Traffic Analysis: A Comprehensive Guide
1 min read Feb 27, 2026

Wireshark Traffic Analysis: A Comprehensive Guide

A Complete Guide to Solving TryHackMe’s Wireshark Traffic Analysis Room - A Step-by-Step Walkthrough of All Tasks and Insights

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis packet-analysis network-forensics tryhackme
Network Forensics with NetworkMiner
2 min read Nov 13, 2025

Network Forensics with NetworkMiner

Investigating PCAP files and email metadata

Raúl Vázquez González's Picture
Raúl Vázquez González in networkminer network-forensics pcap-analysis tryhackme
12 posts tagged

network-security

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
7 min read Apr 27, 2026

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in network-security network-forensics incident-response wireshark log-analysis
Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules
2 min read Feb 12, 2026

Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules

Identifying cleartext credentials inside packet captures and generating actionable firewall rules

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security blue-team tryhackme
Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS
2 min read Jan 14, 2026

Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS

Unlocking Encrypted Traffic - From TLS Handshake to Decrypted HTTP/2 Data

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis tryhackme
Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis
2 min read Dec 30, 2025

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis

Anomalous user agents, subtle anomalies in packet data and specific attack patterns

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis network-security pcap-analysis tryhackme
Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis
3 min read Dec 22, 2025

Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis

ICMP and DNS exfiltration techniques and malicious cleartext FTP behavior

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security threat-detection blue-team
Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos
1 min read Dec 10, 2025

Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos

Practical examples of how to use Wireshark to answer specific questions about network activity

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis digital-forensics
Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs
4 min read Dec 10, 2025

Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs

TryHackMe — Network Security Essentials (Task 7 Practical Exercise)

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem network-security blue-team
Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle
2 min read Dec 2, 2025

Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle

Analyzing network traffic to identify ARP requests, HTTP packets, and sniffed login credentials

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis mitm
Wireshark Traffic Analysis: Nmap Scans
2 min read Nov 24, 2025

Wireshark Traffic Analysis: Nmap Scans

Investigating a .pcap file to analyze a suspected Nmap scan

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark nmap network-security packet-analysis
Mastering Snort: Stopping Real-Time Attacks
3 min read Nov 10, 2025

Mastering Snort: Stopping Real-Time Attacks

Learn how to detect and block brute-force and reverse shell attacks using Snort IDS/IPS

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts
4 min read Nov 8, 2025

Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts

Fine-tune Snort rules for effective packet analysis

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Snort Challenge: The Basics Writeup
23 min read Nov 8, 2025

Snort Challenge: The Basics Writeup

A hands-on walkthrough covering Snort IDS rule creation, traffic analysis, signature-based detection and troubleshooting

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
2 posts tagged

networking

6 Real Problems I Solved While Building My SOC Homelab
10 min read Jun 17, 2026

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team networking
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
1 post tagged

networkminer

Network Forensics with NetworkMiner
2 min read Nov 13, 2025

Network Forensics with NetworkMiner

Investigating PCAP files and email metadata

Raúl Vázquez González's Picture
Raúl Vázquez González in networkminer network-forensics pcap-analysis tryhackme
1 post tagged

nmap

Wireshark Traffic Analysis: Nmap Scans
2 min read Nov 24, 2025

Wireshark Traffic Analysis: Nmap Scans

Investigating a .pcap file to analyze a suspected Nmap scan

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark nmap network-security packet-analysis
1 post tagged

opencti

USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise
3 min read Sep 15, 2025

USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise

Identifying Tactics, Techniques and Procedures of an APT

Raúl Vázquez González's Picture
Raúl Vázquez González in threat-intelligence mitre opencti
1 post tagged

osint

A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine
4 min read Apr 13, 2026

A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine

A practical walkthrough of SOC investigation techniques, including IOC analysis, malware classification, and MITRE ATT\&CK mapping

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-intelligence osint tryhackme
5 posts tagged

packet-analysis

Wireshark Traffic Analysis: A Comprehensive Guide
1 min read Feb 27, 2026

Wireshark Traffic Analysis: A Comprehensive Guide

A Complete Guide to Solving TryHackMe’s Wireshark Traffic Analysis Room - A Step-by-Step Walkthrough of All Tasks and Insights

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis packet-analysis network-forensics tryhackme
Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS
2 min read Jan 14, 2026

Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS

Unlocking Encrypted Traffic - From TLS Handshake to Decrypted HTTP/2 Data

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis tryhackme
Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos
1 min read Dec 10, 2025

Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos

Practical examples of how to use Wireshark to answer specific questions about network activity

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis digital-forensics
Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle
2 min read Dec 2, 2025

Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle

Analyzing network traffic to identify ARP requests, HTTP packets, and sniffed login credentials

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis mitm
Wireshark Traffic Analysis: Nmap Scans
2 min read Nov 24, 2025

Wireshark Traffic Analysis: Nmap Scans

Investigating a .pcap file to analyze a suspected Nmap scan

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark nmap network-security packet-analysis
2 posts tagged

pcap-analysis

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis
2 min read Dec 30, 2025

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis

Anomalous user agents, subtle anomalies in packet data and specific attack patterns

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis network-security pcap-analysis tryhackme
Network Forensics with NetworkMiner
2 min read Nov 13, 2025

Network Forensics with NetworkMiner

Investigating PCAP files and email metadata

Raúl Vázquez González's Picture
Raúl Vázquez González in networkminer network-forensics pcap-analysis tryhackme
3 posts tagged

phishing

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2
10 min read May 13, 2026

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

Raúl Vázquez González's Picture
Raúl Vázquez González in dfir phishing malware-analysis volatility
Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books
7 min read Apr 13, 2026

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books

A SOC phishing analysis; email header forensics, obfuscated payload decoding, and adversary attribution

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst phishing threat-intelligence tryhackme
Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs
3 min read Nov 21, 2025

Exposing a Vast Phishing Campaign by Probing Malicious Emails and URLs

TryHackMe Snapped Phish-ing Line Room Write‑Up

Raúl Vázquez González's Picture
Raúl Vázquez González in phishing incident-response dfir tryhackme
3 posts tagged

powershell

Investigating Suspicious PowerShell Activity with Splunk
9 min read Jun 23, 2026

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk powershell
Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
8 min read Jan 7, 2026

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell

TryHackMe Sysmon Task 10 - Practical Investigations Explained (With PowerShell)

Raúl Vázquez González's Picture
Raúl Vázquez González in sysmon incident-response powershell blue-team tryhackme
Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef
5 min read Oct 13, 2025

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef

A detailed writeup of TryHackMe’s “Investigating with Splunk” final question

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk cyberchef powershell blue-team tryhackme
1 post tagged

programming

Efficient Algorithm for Allow List File Updates in Python
3 min read Oct 13, 2025

Efficient Algorithm for Allow List File Updates in Python

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in python allowlist programming
1 post tagged

python

Efficient Algorithm for Allow List File Updates in Python
3 min read Oct 13, 2025

Efficient Algorithm for Allow List File Updates in Python

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in python allowlist programming
2 posts tagged

ransomware

SOC Alert: Conti Ransomware Investigation
18 min read May 21, 2026

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in soc splunk ransomware incident-response threat-hunting
Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
12 min read May 5, 2026

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

Raúl Vázquez González's Picture
Raúl Vázquez González in ransomware threat-hunting splunk tryhackme aws
1 post tagged

regex

Regular Expressions
3 min read Feb 23, 2026

Regular Expressions

A TryHackMe Regex Practical Exercise Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in regex intrusion-detection tryhackme
1 post tagged

security-audit

Conducting a Security Audit
3 min read Sep 4, 2025

Conducting a Security Audit

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in security-audit compliance data-protection
6 posts tagged

siem

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals
8 min read May 26, 2026

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals

A hands-on path into modern blue team operations

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst blue-team dfir siem certifications
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)
8 min read Mar 27, 2026

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)
9 min read Mar 20, 2026

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice
9 min read Feb 25, 2026

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk certification spl dashboards
Leveraging Splunk SIEM to Detect DoS Attacks
3 min read Dec 24, 2025

Leveraging Splunk SIEM to Detect DoS Attacks

TryHackMe Detecting Web DDoS Room, Task 5 Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk ddos web-security tryhackme
Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs
4 min read Dec 10, 2025

Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs

TryHackMe — Network Security Essentials (Task 7 Practical Exercise)

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem network-security blue-team
3 posts tagged

snort

Mastering Snort: Stopping Real-Time Attacks
3 min read Nov 10, 2025

Mastering Snort: Stopping Real-Time Attacks

Learn how to detect and block brute-force and reverse shell attacks using Snort IDS/IPS

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts
4 min read Nov 8, 2025

Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts

Fine-tune Snort rules for effective packet analysis

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Snort Challenge: The Basics Writeup
23 min read Nov 8, 2025

Snort Challenge: The Basics Writeup

A hands-on walkthrough covering Snort IDS rule creation, traffic analysis, signature-based detection and troubleshooting

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
2 posts tagged

soc

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
SOC Alert: Conti Ransomware Investigation
18 min read May 21, 2026

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in soc splunk ransomware incident-response threat-hunting
10 posts tagged

soc-analyst

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals
8 min read May 26, 2026

CyberDefenders CCDL1:  Practical SOC Analyst Training Beyond the Fundamentals

A hands-on path into modern blue team operations

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst blue-team dfir siem certifications
Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance
11 min read Apr 21, 2026

Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst splunk threat-hunting tryhackme
Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
9 min read Apr 13, 2026

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst incident-response threat-hunting xdr tryhackme
Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books
7 min read Apr 13, 2026

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books

A SOC phishing analysis; email header forensics, obfuscated payload decoding, and adversary attribution

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst phishing threat-intelligence tryhackme
A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine
4 min read Apr 13, 2026

A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine

A practical walkthrough of SOC investigation techniques, including IOC analysis, malware classification, and MITRE ATT\&CK mapping

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-intelligence osint tryhackme
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)
8 min read Mar 27, 2026

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)
9 min read Mar 20, 2026

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup
7 min read Mar 12, 2026

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

A practical SOC-style investigation walkthrough using Windows telemetry to identify attacker activity and defense evasion techniques.

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-hunting splunk tryhackme
Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup
3 min read Mar 5, 2026

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup

A practical SOC analyst investigation of malicious hashes, phishing techniques, and malware delivery chains from the Invite Only TryHackMe room

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst malware-analysis threat-intelligence virustotal tryhackme
6 posts tagged

soc-lab

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Suspicious PowerShell Activity with Splunk
9 min read Jun 23, 2026

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk powershell
6 Real Problems I Solved While Building My SOC Homelab
10 min read Jun 17, 2026

6 Real Problems I Solved While Building My SOC Homelab

Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team networking
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
6 min read Jun 4, 2026

I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?

Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk
1 post tagged

spl

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice
9 min read Feb 25, 2026

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk certification spl dashboards
17 posts tagged

splunk

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Designing an Operational Monitoring Dashboard for Authentication, Endpoint, Network, and Threat Hunting Visibility

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory environment

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk active-directory kerberos detection-engineering
Investigating Suspicious PowerShell Activity with Splunk
9 min read Jun 23, 2026

Investigating Suspicious PowerShell Activity with Splunk

Simulating common PowerShell abuse techniques and investigating endpoint telemetry in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab splunk powershell
SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk
9 min read Jun 7, 2026

Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon and Splunk

Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk networking
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
6 min read Jun 4, 2026

I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?

Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense

Raúl Vázquez González's Picture
Raúl Vázquez González in homelab soc-lab cybersecurity-lab blue-team splunk
SOC Alert: Conti Ransomware Investigation
18 min read May 21, 2026

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in soc splunk ransomware incident-response threat-hunting
Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
12 min read May 5, 2026

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

Raúl Vázquez González's Picture
Raúl Vázquez González in ransomware threat-hunting splunk tryhackme aws
Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance
11 min read Apr 21, 2026

Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst splunk threat-hunting tryhackme
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)
8 min read Mar 27, 2026

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)
9 min read Mar 20, 2026

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup
7 min read Mar 12, 2026

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

A practical SOC-style investigation walkthrough using Windows telemetry to identify attacker activity and defense evasion techniques.

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-hunting splunk tryhackme
How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice
9 min read Feb 25, 2026

How I Built a Splunk Homelab for Splunk Certified Core User (SPLK-1001) — Installation, SPL Queries & Dashboard Practice

A step-by-step hands-on lab to practice Windows log ingestion, SPL commands, reporting and dashboard creation using Splunk Enterprise

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk certification spl dashboards
Leveraging Splunk SIEM to Detect DoS Attacks
3 min read Dec 24, 2025

Leveraging Splunk SIEM to Detect DoS Attacks

TryHackMe Detecting Web DDoS Room, Task 5 Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk ddos web-security tryhackme
Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs
4 min read Dec 10, 2025

Splunk Incident Response: Reconstructing an Attack Using Perimeter Logs

TryHackMe — Network Security Essentials (Task 7 Practical Exercise)

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem network-security blue-team
Cloud-based Threat Detection with Splunk
4 min read Nov 26, 2025

Cloud-based Threat Detection with Splunk

Solving Rotten Cloud Investigation — Blue Team Labs Online (Halloween 2025 Special Event)

Raúl Vázquez González's Picture
Raúl Vázquez González in cloud-security splunk azure-security btlo
Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef
5 min read Oct 13, 2025

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef

A detailed writeup of TryHackMe’s “Investigating with Splunk” final question

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk cyberchef powershell blue-team tryhackme
1 post tagged

sql

Apply Filters to SQL Queries: A Cybersecurity Use Case
3 min read Sep 22, 2025

Apply Filters to SQL Queries: A Cybersecurity Use Case

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in sql data-filtering threat-hunting
1 post tagged

sysmon

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
8 min read Jan 7, 2026

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell

TryHackMe Sysmon Task 10 - Practical Investigations Explained (With PowerShell)

Raúl Vázquez González's Picture
Raúl Vázquez González in sysmon incident-response powershell blue-team tryhackme
1 post tagged

threat-detection

Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis
3 min read Dec 22, 2025

Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis

ICMP and DNS exfiltration techniques and malicious cleartext FTP behavior

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security threat-detection blue-team
9 posts tagged

threat-hunting

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
8 min read Jun 15, 2026

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

Raúl Vázquez González's Picture
Raúl Vázquez González in soc soc-analyst mitre-attck blue-team incident-response threat-hunting splunk
SOC Alert: Conti Ransomware Investigation
18 min read May 21, 2026

SOC Alert: Conti Ransomware Investigation

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in soc splunk ransomware incident-response threat-hunting
Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
12 min read May 5, 2026

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

Raúl Vázquez González's Picture
Raúl Vázquez González in ransomware threat-hunting splunk tryhackme aws
Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance
11 min read Apr 21, 2026

Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst splunk threat-hunting tryhackme
Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
9 min read Apr 13, 2026

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst incident-response threat-hunting xdr tryhackme
Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup
7 min read Mar 12, 2026

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

A practical SOC-style investigation walkthrough using Windows telemetry to identify attacker activity and defense evasion techniques.

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-hunting splunk tryhackme
Searching, Filtering, and Correlation: Threat Hunting with Brim
4 min read Dec 4, 2025

Searching, Filtering, and Correlation: Threat Hunting with Brim

Using Brim capabilities to identify malicious activities

Raúl Vázquez González's Picture
Raúl Vázquez González in brim threat-hunting network-analysis tryhackme
My Experience with the Blue Team Level 1 (BTL1) Certification
4 min read Oct 16, 2025

My Experience with the Blue Team Level 1 (BTL1) Certification

A Broad and Professional Blue-Team Skillset

Raúl Vázquez González's Picture
Raúl Vázquez González in blue-team certifications incident-response digital-forensics threat-hunting
Apply Filters to SQL Queries: A Cybersecurity Use Case
3 min read Sep 22, 2025

Apply Filters to SQL Queries: A Cybersecurity Use Case

Practical experience with the Google Cybersecurity Certificate

Raúl Vázquez González's Picture
Raúl Vázquez González in sql data-filtering threat-hunting
4 posts tagged

threat-intelligence

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books
7 min read Apr 13, 2026

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books

A SOC phishing analysis; email header forensics, obfuscated payload decoding, and adversary attribution

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst phishing threat-intelligence tryhackme
A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine
4 min read Apr 13, 2026

A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine

A practical walkthrough of SOC investigation techniques, including IOC analysis, malware classification, and MITRE ATT\&CK mapping

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-intelligence osint tryhackme
Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup
3 min read Mar 5, 2026

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup

A practical SOC analyst investigation of malicious hashes, phishing techniques, and malware delivery chains from the Invite Only TryHackMe room

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst malware-analysis threat-intelligence virustotal tryhackme
USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise
3 min read Sep 15, 2025

USBferry, Tropic Trooper, and ATT&CK: A Practical CTI Exercise

Identifying Tactics, Techniques and Procedures of an APT

Raúl Vázquez González's Picture
Raúl Vázquez González in threat-intelligence mitre opencti
27 posts tagged

tryhackme

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
12 min read May 5, 2026

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

Raúl Vázquez González's Picture
Raúl Vázquez González in ransomware threat-hunting splunk tryhackme aws
Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance
11 min read Apr 21, 2026

Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst splunk threat-hunting tryhackme
Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
9 min read Apr 13, 2026

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst incident-response threat-hunting xdr tryhackme
Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books
7 min read Apr 13, 2026

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books

A SOC phishing analysis; email header forensics, obfuscated payload decoding, and adversary attribution

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst phishing threat-intelligence tryhackme
A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine
4 min read Apr 13, 2026

A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine

A practical walkthrough of SOC investigation techniques, including IOC analysis, malware classification, and MITRE ATT\&CK mapping

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-intelligence osint tryhackme
Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)
8 min read Mar 27, 2026

Splunk 2 TryHackMe Writeup (Part 2) — BOTS v2 SOC Investigation (300 & 400 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)
9 min read Mar 20, 2026

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk siem soc-analyst blue-team tryhackme
Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup
7 min read Mar 12, 2026

Investigating Malicious Activity with Sysmon and Splunk — TryHackMe New Hire Old Artifacts Writeup

A practical SOC-style investigation walkthrough using Windows telemetry to identify attacker activity and defense evasion techniques.

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst threat-hunting splunk tryhackme
Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup
3 min read Mar 5, 2026

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup

A practical SOC analyst investigation of malicious hashes, phishing techniques, and malware delivery chains from the Invite Only TryHackMe room

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst malware-analysis threat-intelligence virustotal tryhackme
Wireshark Traffic Analysis: A Comprehensive Guide
1 min read Feb 27, 2026

Wireshark Traffic Analysis: A Comprehensive Guide

A Complete Guide to Solving TryHackMe’s Wireshark Traffic Analysis Room - A Step-by-Step Walkthrough of All Tasks and Insights

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis packet-analysis network-forensics tryhackme
Regular Expressions
3 min read Feb 23, 2026

Regular Expressions

A TryHackMe Regex Practical Exercise Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in regex intrusion-detection tryhackme
Elastic Stack (ELK) for SOC Log Investigations
4 min read Feb 16, 2026

Elastic Stack (ELK) for SOC Log Investigations

Essential ELK techniques for investigating and querying logs

Raúl Vázquez González's Picture
Raúl Vázquez González in elk elastic elastic-search elastic-stack tryhackme
Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules
2 min read Feb 12, 2026

Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules

Identifying cleartext credentials inside packet captures and generating actionable firewall rules

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security blue-team tryhackme
TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction
3 min read Feb 2, 2026

TryHackMe ShadowTrace Walkthrough: Malware Analysis and IOC Extraction

Complete writeup with binary analysis, string decoding, and DFIR techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in malware-analysis dfir incident-response tryhackme
How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide
8 min read Jan 26, 2026

How I Passed TryHackMe’s Security Analyst Level 1 (SAL1): A Practical Study Guide

A breakdown of the SAL1 exam, its SOC scenarios, tools, and how to prepare effectively using TryHackMe

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
Detecting Web Shells in WordPress Through Apache Log Analysis
3 min read Jan 21, 2026

Detecting Web Shells in WordPress Through Apache Log Analysis

A TryHackMe writeup from the “Detecting Web Shells” room — Task 6 Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in web-security incident-response blue-team tryhackme
Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS
2 min read Jan 14, 2026

Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS

Unlocking Encrypted Traffic - From TLS Handshake to Decrypted HTTP/2 Data

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis tryhackme
Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell
8 min read Jan 7, 2026

Sysmon Investigation Walkthrough, Using Event Viewer and PowerShell

TryHackMe Sysmon Task 10 - Practical Investigations Explained (With PowerShell)

Raúl Vázquez González's Picture
Raúl Vázquez González in sysmon incident-response powershell blue-team tryhackme
Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis
2 min read Dec 30, 2025

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis

Anomalous user agents, subtle anomalies in packet data and specific attack patterns

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis network-security pcap-analysis tryhackme
Leveraging Splunk SIEM to Detect DoS Attacks
3 min read Dec 24, 2025

Leveraging Splunk SIEM to Detect DoS Attacks

TryHackMe Detecting Web DDoS Room, Task 5 Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk ddos web-security tryhackme
Searching, Filtering, and Correlation: Threat Hunting with Brim
4 min read Dec 4, 2025

Searching, Filtering, and Correlation: Threat Hunting with Brim

Using Brim capabilities to identify malicious activities

Raúl Vázquez González's Picture
Raúl Vázquez González in brim threat-hunting network-analysis tryhackme
Network Forensics with NetworkMiner
2 min read Nov 13, 2025

Network Forensics with NetworkMiner

Investigating PCAP files and email metadata

Raúl Vázquez González's Picture
Raúl Vázquez González in networkminer network-forensics pcap-analysis tryhackme
The new TryHackMe SOC Level 1 Path
7 min read Nov 10, 2025

The new TryHackMe SOC Level 1 Path

Now getting ready for the job got even better

Raúl Vázquez González's Picture
Raúl Vázquez González in certifications blue-team tryhackme
Mastering Snort: Stopping Real-Time Attacks
3 min read Nov 10, 2025

Mastering Snort: Stopping Real-Time Attacks

Learn how to detect and block brute-force and reverse shell attacks using Snort IDS/IPS

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts
4 min read Nov 8, 2025

Mastering Snort Rule Creation: A Step-by-Step Guide for Network Analysts

Fine-tune Snort rules for effective packet analysis

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Snort Challenge: The Basics Writeup
23 min read Nov 8, 2025

Snort Challenge: The Basics Writeup

A hands-on walkthrough covering Snort IDS rule creation, traffic analysis, signature-based detection and troubleshooting

Raúl Vázquez González's Picture
Raúl Vázquez González in snort network-security intrusion-detection tryhackme
Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef
5 min read Oct 13, 2025

Investigating and Decrypting PowerShell Web Requests with Splunk and CyberChef

A detailed writeup of TryHackMe’s “Investigating with Splunk” final question

Raúl Vázquez González's Picture
Raúl Vázquez González in splunk cyberchef powershell blue-team tryhackme
1 post tagged

ufw

Linux Workstation Hardening: Enhancing Security with UFW
7 min read Oct 2, 2025

Linux Workstation Hardening: Enhancing Security with UFW

Master UFW and Kernel Hardening to Fortify Your Linux Workstation Against Threats

Raúl Vázquez González's Picture
Raúl Vázquez González in ufw linux-security linux-hardening firewall
1 post tagged

virustotal

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup
3 min read Mar 5, 2026

Invite Only: A Threat Intelligence Investigation and Malware Analysis writeup

A practical SOC analyst investigation of malicious hashes, phishing techniques, and malware delivery chains from the Invite Only TryHackMe room

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst malware-analysis threat-intelligence virustotal tryhackme
1 post tagged

volatility

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2
10 min read May 13, 2026

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

Raúl Vázquez González's Picture
Raúl Vázquez González in dfir phishing malware-analysis volatility
2 posts tagged

web-security

Detecting Web Shells in WordPress Through Apache Log Analysis
3 min read Jan 21, 2026

Detecting Web Shells in WordPress Through Apache Log Analysis

A TryHackMe writeup from the “Detecting Web Shells” room — Task 6 Investigation

Raúl Vázquez González's Picture
Raúl Vázquez González in web-security incident-response blue-team tryhackme
Leveraging Splunk SIEM to Detect DoS Attacks
3 min read Dec 24, 2025

Leveraging Splunk SIEM to Detect DoS Attacks

TryHackMe Detecting Web DDoS Room, Task 5 Writeup

Raúl Vázquez González's Picture
Raúl Vázquez González in siem splunk ddos web-security tryhackme
1 post tagged

windows-forensics

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives
3 min read Nov 10, 2025

Windows Forensics: How I Traced Suspicious Activity Using Registry Hives

Using Eric Zimmerman’s Registry Explorer to locate key forensic artifacts

Raúl Vázquez González's Picture
Raúl Vázquez González in ez-tools digital-forensics windows-forensics dfir
9 posts tagged

wireshark

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
7 min read Apr 27, 2026

Exposing a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

Raúl Vázquez González's Picture
Raúl Vázquez González in network-security network-forensics incident-response wireshark log-analysis
Wireshark Traffic Analysis: A Comprehensive Guide
1 min read Feb 27, 2026

Wireshark Traffic Analysis: A Comprehensive Guide

A Complete Guide to Solving TryHackMe’s Wireshark Traffic Analysis Room - A Step-by-Step Walkthrough of All Tasks and Insights

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis packet-analysis network-forensics tryhackme
Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules
2 min read Feb 12, 2026

Wireshark Traffic Analysis: Cleartext Credentials & Firewall Rules

Identifying cleartext credentials inside packet captures and generating actionable firewall rules

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security blue-team tryhackme
Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS
2 min read Jan 14, 2026

Wireshark Traffic Analysis: Encrypted Protocol Analysis: Decrypting HTTPS

Unlocking Encrypted Traffic - From TLS Handshake to Decrypted HTTP/2 Data

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis tryhackme
Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis
2 min read Dec 30, 2025

Wireshark Traffic Analysis: HTTP Cleartext Protocol Analysis

Anomalous user agents, subtle anomalies in packet data and specific attack patterns

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-analysis network-security pcap-analysis tryhackme
Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis
3 min read Dec 22, 2025

Wireshark Traffic Analysis: DNS and ICMP Traffic Tunneling & FTP Cleartext Protocol Analysis

ICMP and DNS exfiltration techniques and malicious cleartext FTP behavior

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security threat-detection blue-team
Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos
1 min read Dec 10, 2025

Wireshark Traffic Analysis: Identifying Hosts: DHCP, NetBIOS and Kerberos

Practical examples of how to use Wireshark to answer specific questions about network activity

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis digital-forensics
Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle
2 min read Dec 2, 2025

Wireshark Traffic Analysis: ARP Poisoning & Man In The Middle

Analyzing network traffic to identify ARP requests, HTTP packets, and sniffed login credentials

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark network-security packet-analysis mitm
Wireshark Traffic Analysis: Nmap Scans
2 min read Nov 24, 2025

Wireshark Traffic Analysis: Nmap Scans

Investigating a .pcap file to analyze a suspected Nmap scan

Raúl Vázquez González's Picture
Raúl Vázquez González in wireshark nmap network-security packet-analysis
1 post tagged

xdr

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
9 min read Apr 13, 2026

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

Raúl Vázquez González's Picture
Raúl Vázquez González in soc-analyst incident-response threat-hunting xdr tryhackme

Latest Posts

Building a Tier 1 SOC Dashboard in Splunk
10 min read Jul 8, 2026

Building a Tier 1 SOC Dashboard in Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
8 min read Jul 2, 2026

Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk

Raúl Vázquez González's Picture
Raúl Vázquez González

Explore Tags

active-directory allowlist aws azure-security blue-team bluetooth books brim btlo certification certifications chmod cloud-security compliance cyber-security-awareness cyberchef cybercrime cybersecurity cybersecurity-lab dashboards data-filtering data-protection ddos detection-engineering dfir dfir tryhackme digital-forensics elastic elastic-search elastic-stack elk ez-tools file-permissions firewall homelab incident-response infosec intrusion-detection kerberos linux-hardening linux-security log-analysis malware-analysis mitm mitre mitre-attck network-analysis network-forensics network-security networking networkminer nmap opencti osint packet-analysis pcap-analysis phishing powershell programming python ransomware regex security-audit siem snort soc soc-analyst soc-lab spl splunk sql sysmon threat-detection threat-hunting threat-intelligence tryhackme ufw virustotal volatility web-security windows-forensics wireshark xdr
2026 © Citadel Cybersec.