It takes 20 years to build a reputation and a few minutes of a cyber incident to ruin it. — Stéphane Nappo

A security-minded SOC Analyst trainee focused on strategic threat analysis, decisive incident response, and proactive risk awareness — combining disciplined investigation, critical thinking, and continuous improvement to strengthen organizational resilience.

Background & Philosophy

About Me

I'm an entry-level SOC Analyst with a strong foundation in cybersecurity, built through certified coursework — including ISC2's Networks and Communications Security and Google's cybersecurity and cloud security fundamentals — combined with hands-on practice through simulated security labs. I've consistently developed my skills through platforms such as TryHackMe, where I ranked among the global top 3%, and CyberDefenders, achieving a global rank of 2,584 and a national rank of 155.

Beyond technical knowledge, I bring a security-first mindset built around analytical thinking, curiosity, attention to detail, disciplined investigation, clear communication, teamwork, adaptability, patience, and a commitment to continuous learning. As I begin my professional journey, my goal is to approach every security event with an open mind, understand the context behind it, and contribute thoughtfully to the team.

I believe credentials provide the foundation, but the way I think, learn, investigate, and grow tells the bigger story. Explore my certifications, hands-on experience, labs, and projects to get to know me better.

Projects

Operational security defense engineering, interactive portfolios, and tactical automation frameworks. Tap any project to explore full architectural details.

01 / ARCHITECTURE DEMO

WFCR Engine Overview

Practical Range Operations

Hands-on Experience

Rigorous simulation of enterprise security operations, real-world attack emulation, and blue team incident investigations across elite cybersecurity training platforms.

TryHackMe Operations

Top 3% Global Rank View Official Profile ↗
Summary & Approach

Engaged in comprehensive security operations paths focusing on continuous log monitoring, vulnerability identification, and defensive security hardening. Executed hands-on triage workflows across Linux and Windows lab architectures to detect unauthorized access.

// Walkthrough & Paths

Snort

Description

Learn how to effectively use the Snort intrusion detection system to monitor network traffic for real-time threats, analyze captured traffic files, and accurately identify malicious anomalies.

Elastic Stack: The Basics

Description

Understand the core components of the Elastic Stack (ELK) and how Security Operations Center analysts leverage this powerful toolset to conduct comprehensive log investigations and threat hunting.

Introduction to SOAR

Description

Explore the core concepts and underlying methodologies of Security Orchestration, Automation, and Response to streamline incident handling and improve overall security operations efficiency.

Network Discovery Detection

Description

Understand the various techniques attackers use to map and discover assets within a target network, and learn the corresponding strategies to effectively detect this reconnaissance activity.

Data Exfiltration Detection

Description

Discover the methods used by adversaries to extract sensitive information from a compromised network and learn how to proactively detect these data exfiltration attempts across multiple channels.

Wireshark: Traffic Analysis

Description

Learn the foundational concepts of analyzing network traffic using Wireshark, focusing on practical techniques to identify, investigate, and mitigate potential network anomalies and security threats.

MITRE

Description

Explore the various frameworks and extensive knowledge bases that MITRE provides to the cybersecurity community, learning how to leverage these resources to enhance threat intelligence and defensive postures.

Windows Threat Detection 1

Description

Investigate the most common initial access techniques utilized by attackers targeting Windows environments, and learn the specific detection mechanisms required to identify these early-stage breaches.

Windows Threat Detection 2

Description

Analyze the critical first steps threat actors take immediately following a successful Windows breach, learning how to detect early post-compromise activities and lateral movement indicators.

Windows Threat Detection 3

Description

Examine the persistence mechanisms that threat actors deploy to maintain unauthorized access to compromised Windows hosts over extended periods, and learn how to identify these stealthy backdoors.

Linux Threat Detection 1

Description

Explore the various vectors attackers use to compromise Linux systems, focusing on how to effectively monitor and detect these initial intrusion attempts by thoroughly analyzing system logs.

Linux Threat Detection 2

Description

Investigate the immediate post-exploitation actions taken by attackers upon breaching a Linux server, learning practical techniques to detect early reconnaissance and privilege escalation attempts within the environment.

Intro to Malware Analysis

Description

Understand the foundational steps and methodologies required to safely analyze and investigate suspected malware samples within a controlled environment.

Log Analysis with SIEM

Description

Explore how Security Information and Event Management solutions aggregate and analyze system logs to effectively detect and investigate malicious network behavior.

IP and Domain Threat Intel

Description

Learn practical techniques for gathering and utilizing open-source threat intelligence to enrich your understanding and contextualization of suspicious IP addresses and domains.

Alert Triage With Splunk

Description

Master the use of Splunk's search capabilities to efficiently triage security alerts, investigate potential threats, and pinpoint malicious activity within your infrastructure.

Linux Threat Detection 3

Description

Examine the final stages of cyberattacks targeting Linux environments and learn how to accurately identify critical indicators of compromise embedded within system logs.

Alert Triage With Elastic

Description

Develop essential skills to investigate security alerts using the Elastic Stack, comprehensively analyzing log data to effectively spot and respond to emerging threats.

Phishing Analysis Fundamentals

Description

Delve into the technical components that make up an email, learning how to dissect email headers and body content to identify sophisticated phishing attempts.

Intro to Cyber Threat Intel

Description

Gain an introduction to the core concepts of cyber threat intelligence, exploring relevant industry standards, essential frameworks, and the intelligence lifecycle.

File and Hash Threat Intel

Description

Discover practical methodologies for enriching file and hash artifacts using various threat intelligence sources to quickly determine their potential maliciousness and scope.

Malware Classification

Description

Learn the key characteristics and defining features used to identify, classify, and deeply understand the behaviors of the most common malware types.

Living Off the Land Attacks

Description

Understand how sophisticated adversaries leverage trusted, built-in Windows administrative tools to conduct stealthy attacks, and learn effective detection strategies to uncover them.

Pyramid Of Pain

Description

Understand the fundamental concept of the Pyramid of Pain framework, learning how it effectively categorizes and ranks threat indicators based on the level of difficulty they pose for adversaries to change.

Cyber Kill Chain

Description

Explore the Cyber Kill Chain framework, a critical model designed for identifying and preventing network intrusions by understanding the specific, sequential steps adversaries must take to achieve their malicious objectives.

Unified Kill Chain

Description

Learn about the Unified Kill Chain framework, discovering how it establishes the distinct phases of a cyberattack and provides a structured methodology for identifying vulnerabilities and mitigating risks to IT assets.

Eviction

Description

Uncover hidden threats and persistent mechanisms operating within a compromised system, learning practical investigative techniques to effectively identify and evict malicious activity lurking beneath the surface.

Windows Logging for SOC

Description

Begin your journey into Windows environment monitoring by understanding key system logs, learning how to configure, collect, and analyze these logs effectively to proactively detect potential security threats.

Detecting Web Shells

Description

Dive into the methodologies for detecting malicious web shells by conducting comprehensive analyses across multiple domains, including server logs, file system modifications, and anomalous network traffic patterns.

Linux Logging for SOC

Description

Familiarize yourself with the essential Linux log sources and understand their critical importance in security operations, learning how to effectively leverage them during routine SOC alert triage and incident investigations.

Detecting Web DDoS

Description

Gain a comprehensive understanding of various denial-of-service attack vectors, exploring practical detection techniques and implementing effective mitigation strategies to protect web infrastructure from disruptive DDoS campaigns.

Junior Security Analyst Intro

Description

Step into the role of a Junior Security Analyst to experience a typical day in the life, performing routine daily duties and understanding core operational workflows.

NetworkMiner

Description

Master the usage of NetworkMiner for analyzing captured network traffic files, allowing you to practice essential network forensics activities and extract valuable network artifacts.

Wireshark: The Basics

Description

Gain a solid foundation in using Wireshark, covering the essential skills needed to navigate the interface, analyze various network protocols, and inspect PCAP files effectively.

Wireshark: Packet Operations

Description

Dive deeper into packet analysis fundamentals using Wireshark, learning advanced filtering and searching techniques to locate specific data and pinpoint the exact information you need.

Enumeration & Brute Force

Description

Understand the techniques attackers use to enumerate system information and execute brute force attacks against various authentication mechanisms to test and validate system security.

Session Management

Description

Explore the core concepts of session management in web applications, detailing the different types of attacks that exploit insecure session implementations and how to prevent them.

SOC L1 Alert Triage

Description

Gain a deeper understanding of Security Operations Center (SOC) alerts, building a structured and systematic approach to efficiently analyze, prioritize, and triage incoming security events.

SOC L1 Alert Reporting

Learn the critical communication skills required in a SOC, focusing on how to properly document, report, and escalate high-risk security alerts to the appropriate stakeholders.

SOC Workbooks and Lookups

Description

Discover and leverage useful corporate resources, such as workbooks and threat intelligence lookups, to help structure, streamline, and simplify the L1 alert triage process.

SOC Metrics and Objectives

Description

Explore the key performance metrics that drive the overall effectiveness of a Security Operations Center, and discover actionable strategies to continuously improve operations.

Humans as Attack Vectors

Description

Understand the psychological and tactical reasons why humans are frequently targeted in cyber attacks, and explore how the SOC plays a crucial role in defending against social engineering.

Systems as Attack Vectors

Description

Learn the methodologies attackers use to identify and exploit vulnerable or misconfigured computer systems, along with the defensive strategies required to secure and protect them.

SOC Role in Blue Team

Description

Discover the various security roles within a Blue Team environment and chart a path for advancing your career in cybersecurity, starting from the foundational L1 analyst position.

Network Security Essentials

Description

Learn about the fundamental principles and key aspects of network security, including how to properly monitor network infrastructure and protect it against sophisticated adversaries.

Network Traffic Basics

Description

Understand the core concepts of network analysis, exploring why it is an essential skill, how to properly collect network traffic, and a review of the various tools available.

Introduction to SIEM

Description

Grasp the fundamental concepts of Security Information and Event Management systems, exploring their key features, core functionalities, and crucial role in centralizing security monitoring.

Splunk: The Basics

Description

Gain a foundational understanding of Splunk, focusing on how SOC analysts utilize its powerful search and reporting capabilities to effectively investigate security logs and trace incidents.

IDS Fundamentals

Description

Learn the essential principles behind Intrusion Detection Systems and gain practical, hands-on experience by working with Snort to monitor and evaluate suspicious network activity.

Web Security Essentials

Description

Explore the underlying mechanics of how the web functions, identify the most common website security vulnerabilities, and learn the essential protective measures required for a safer internet experience.

Detecting Web Attacks

Description

Dive into common web-based attacks and learn practical detection methodologies by thoroughly analyzing both web server logs and underlying network traffic for signs of compromise.

Man-in-the-Middle Detection

Description

Understand the mechanics of Man-in-the-Middle (MITM) attacks and learn how to effectively analyze network traffic to identify the subtle footprints left behind by this type of interception.

Introduction to EDR

Description

Learn the foundational concepts of Endpoint Detection and Response solutions, exploring their core features, operational mechanics, and importance in securing individual host machines.

OWASP Top 10 2025: IAAA Failures

Description

Delve into specific OWASP Top 10 vulnerabilities (A01, A07, and A09) and understand how these critical security risks relate directly to failures in applying the IAAA access control model.

OWASP Top 10 2025: Application Design Flaws

Description

Examine critical OWASP Top 10 categories (A02, A03, A06, and A10) to understand how fundamental application design flaws can introduce severe security risks and potential compromises.

// Challenge & CTF Rooms

Boogeyman 1

Description

Focused on a multi-layered digital forensics investigation—starting with email header analysis to trace the initial phishing vector, moving into endpoint artifact review to spot malicious invoice payloads, and finishing with network traffic inspection. The conclusion successfully mapped out the entire attack lifecycle, identifying how the threat actor infiltrated the environment, delivered the payload, and triggered outbound communication to fully resolve the incident.

Boogeyman 2

Description

Approach centered on thorough endpoint and log forensics—analyzing malicious spear-phishing artifacts, tracking script and process execution chains, and examining suspicious file payloads to trace the intrusion. The conclusion successfully mapped out the attacker's initial access vector, established how the payload was delivered and executed, and answered all forensic questions to fully close out the incident.

Boogeyman 3

Description

Systematically picking apart artifacts, tracking execution chains, and analyzing suspicious logs and files to reconstruct the attacker's methodology. Wrapping up the investigation brings a satisfying conclusion, successfully uncovering the intrusion vector, tracing lateral movement or persistence mechanisms, and answering all the key forensic questions to close out the case.

Tempest

Description

Analysed log preparations, tracking initial access vectors via malicious documents and stage-2 execution, and evaluating subsequent network traffic. The conclusion successfully mapped out internal reconnaissance, privilege escalation exploits, and the full extent of the compromise, answering all key forensic questions to trace the end-to-end incident.

Warzone 1

Description

Triaged incoming IDS/IPS alerts, inspecting packet captures or logs, and distinguishing between false positives and malicious activity. The conclusion successfully validated the network alert, tracked the source of the malicious traffic, and answered all core forensic questions to close out the security.

Masquerade

Description

Analysed suspicious endpoint artifacts, tracking malicious process masquerading or execution flows, and examining system logs to trace the attacker's activity. The conclusion successfully uncovered the true nature of the anomalous process, mapped out the breach's footprint, and answered all key forensic questions to resolve the incident.

Mayhem

Description

Conducted deep investigative analysis—diving into system files and forensic artifacts to untangle hidden anomalies and trace the attacker's footprint. The conclusion successfully unmasked the core threats, exposed the hidden secrets scattered across the environment, and answered all critical questions to fully resolve the case.

SeeTwo

Description

Focused on command and control (C2) traffic analysis—inspecting network packet captures, identifying beaconing patterns, and analyzing connection payloads to map out the adversary's communication infrastructure. The conclusion successfully exposed the active C2 server, traced the client-server interaction mechanisms, and answered all critical forensic questions to fully neutralize the threat vector.

Snapped Phish-ing Line

Description

The approach focused on email header triage and URL reputation analysis to dissect a coordinated phishing campaign. The conclusion successfully exposed the threat actor's infrastructure, mapped out malicious landing pages, and answered all forensic questions to neutralize the threat.

New Hire Old Artifacts

Description

The approach centered on SIEM log analysis using Splunk—querying event logs, tracking user activity, and correlating historical endpoints. The conclusion successfully reconstructed the newcomer's anomalous footprint, pinpointed the exact point of compromise, and resolved the incident.

Carnage

Description

The approach focused on deep packet inspection and network traffic analysis in Wireshark—filtering streams, isolating suspicious protocol exchanges, and unearthing malicious payloads. The conclusion successfully decoded the attacker's network communications, identified the payload delivery mechanism, and closed out the investigation.

The Greenholt Phish

Description

The approach involved hands-on email artifact examination—inspecting MIME structures, analyzing embedded attachments, and evaluating malicious links. The conclusion successfully classified the phishing vector, exposed the attacker's pretexting strategy, and answered all critical analytical questions.

Phishing Prevention

Description

The approach centered on defense-in-depth principles—reviewing email security controls like SPF, DKIM, and DMARC, alongside user awareness frameworks. The conclusion successfully established robust hardening strategies to mitigate future social engineering risks and secure organizational boundaries.

Investigating Windows 2.0

Description

The approach dove deeper into advanced Windows forensics—analyzing registry hives, event logs, and persistent artifacts left behind by an ongoing intrusion. The conclusion successfully mapped out the attacker's advanced persistence and lateral movement tactics, delivering a comprehensive incident report.

CyberDefenders Investigations

#155 National Rank View Official Profile ↗

Targeted blue team labs focusing on digital forensics, artifact extraction, and post-compromise analysis.

// Endpoint Forensics Labs

Hammered Lab

Description

Learned endpoint forensics by analyzing webserver honeypot logs to detect attacker techniques—including execution, persistence, defense impairment, credential access, and discovery—using Linux command-line tools, grep, and text editors.

Ulysses Lab

Description

Investigated a brute-force attack and persistence using Volatility with a custom Debian profile. Used Autopsy and FTK Imager for memory dump analysis, uncovering unauthorized outbound connections and malicious payloads.

CorporateSecret Lab

Description

Investigated a Windows VM image using FTK Imager, Registry Explorer, RegRipper, HxD, DB Browser, HindSight, Event Log Explorer, and MFTDump.

Szechuan Sauce Lab

Description

Analysed with uncompressing the lab archive—using the password cyberdefenders.org—and analyzing a diverse set of forensic artifacts. These include EnCase disk images (.E01 to .E04), memory dumps (.mem), packet captures (.pcap), and CSV logs to investigate techniques across initial access, execution, persistence, privilege escalation, and stealth.

Sysinternals Lab

Description

Centered around a user who thought they were downloading the legitimate Sysinternals suite, only to find the files unresponsive and their machine progressively slowing down. Diving into the artifacts using tools like Registry Explorer, Event Log Explorer, and Autopsy, I had to piece together the attacker's tactics—focusing heavily on Execution, Command And Control, and Impact. It’s a great, medium-difficulty hands-on case that really sharpens your malware triage and artifact analysis skills.

KrakenKeylogger Lab

Description

Tackling the KrakenKeylogger Lab was an engaging dive into endpoint forensics that really put my investigative skills to the test. Uncovering how an insider threat attempted extortion by locking away a completed assignment required meticulously piecing together the timeline and analyzing techniques spanning initial access, persistence, and exfiltration. Utilizing tools like DB Browser For SQLite, LECmd, and Timeline Explorer made it deeply rewarding to trace the threat actor's steps and ultimately crack the case

Silent Breach Lab

Description

Analysed Windows mail artifacts like Microsoft HxStore.hxd files and employing essential tools such as FTK Imager, SQLite Viewer, Strings, and CyberChef to decode files, extract crucial intel, and uncover the execution tactics behind the cyber attack.

Insider Lab

Description

Investigated the Linux disk image of the malicious employee Karen, you navigated through crucial endpoint forensics techniques—focusing on execution and credential access tactics with tools like FTK Imager. Uncovering the internal illegal activities within TAAUSAI made for a compelling and rewarding challenge, showcasing sharp investigative skills and solid blue team capabilities.

The Crime Lab

Description

Tackling The Crime Lab on CyberDefenders was an engaging exercise in mobile endpoint forensics. Stepping into a murder investigation using the victim's recovered smartphone, I utilized tools like ALEAPP and DB Browser for SQLite to meticulously comb through digital artifacts. By correlating witness statements with data extracted from the device, I successfully traced the timeline of events, pieced together the crucial clues leading up to the incident, and solved the case.

RedLine Lab

Description

Successfully dissected a compromised memory dump to trace the attacker's footsteps, uncover privilege escalation and stealth tactics, and analyze command and control channels. This challenge sharpened my ability to identify specific malware families, understand how NIDS bypass techniques work, and effectively uncover forensic artifacts left behind during an intrusion.

Ramnit Lab

Description

Investigative process involved deep-diving into an endpoint memory dump to trace a sophisticated malware intrusion. Utilizing essential blue team tools like Volatility 3 and VirusTotal, the analysis focused on uncovering suspicious workstation behavior, tracking the malicious actions of the Ramnit infection, and successfully extracting key forensic findings to solve the challenge.

Reveal Lab

Description

used Volatility 3 to dive deep into the memory dump from the compromised financial workstation. By carefully tracing anomalies tied to stealth and discovery tactics, I was able to piece together the attacker's footprint, uncover the breach's origin, and successfully assess the full scope of the incident.

// Threat Intelligence Labs

BRabbit Lab

Description

Focuses on key tactics such as Execution, Persistence, Privilege Escalation, Command and Control, and Impact, while utilizing tools like Malpedia, VirusTotal, ANY.RUN, Email Header Analyzer, and MalwareURL to analyze artifacts and uncover information about the attacker.

Yellow RAT Lab

Description

Revolved around an IT security check at GlobalTech Industries, where abnormal network traffic and employee search queries being redirected to unfamiliar websites prompted a deeper investigation into Initial Access and Execution tactics using tools like VirusTotal and Red Canary.

Oski Lab

Description

Centered around a phishing incident. An accountant received an email titled "Urgent New Order" with an attached malicious invoice containing false information, which subsequently triggered SIEM alerts for a suspicious file download linked to a PowerPoint file.

Tusk Infostealer Lab

Description

Analysed and examined the provided indicators and attack methods to track the threat actor's infrastructure and uncover how credentials were stolen and funds were exfiltrated.

Red Stealer Lab

Description

Analysed the malware's hash using tools like Whois, VirusTotal, MalwareBazaar, ThreatFox, and ANY.RUN to gather actionable intelligence across tactics such as Execution, Persistence, Privilege Escalation, Stealth, Defence Impairment, Discovery, Collection, and Impact to support the Incident Response team.

IcedID Lab

Description

Examined indicators and monitor the activities of this advanced persistent threat (APT) group using analysis tools such as VirusTotal, Malpedia, Tria.Ge, and ANY.RUN.

// Network Forensics Labs

Packetmaze Lab

Description

Conducted deep packet inspection using Wireshark and Network Miner to decrypt traffic, extract malicious payloads, and trace exfiltration paths across complex network layers.

HoneyBOT Lab

Description

Learned PCAP analysis of honeypot interactions and automatic exploitation using Brim, Wireshark, NetworkMiner, Libemu (Sctest), Scdbg, and IP LookUp.

BlueSky Ransomware Lab

Description

Analysed a corporate ransomware security incident to uncover attacker tactics—such as execution, persistence, and impact—using tools like Wireshark, Network Miner, and Windows Event Viewer.

HawkEye Lab

Description

Investigated a simulated security incident where an accountant received a suspicious invoice email containing a download link, leading to malicious network traffic, command-and-control activity, and data exfiltration.

Tomcat Takeover Lab

Description

Analysed a PCAP file to investigate the compromise of an Apache Tomcat web server within a company's intranet and identifying malicious activities spanning several MITRE ATT&CK tactics using tools like Wireshark and NetworkMiner.

PsExec Hunt Lab

Description

The investigation focused on analyzing a PCAP file using Wireshark to trace suspicious lateral movement activity involving PsExec flagged by an Intrusion Detection System (IDS).

Web Investigation Lab

Description

Network forensics challenge focuses on tactics such as Initial Access, Persistence, and Command and Control using tools like Wireshark and Network Miner.

XLMRat Lab

Description

Analysed a PCAP file from a compromised machine exhibiting suspicious network traffic to determine the attack method, identify malicious payloads, and trace the timeline of events.

Lockdown Lab

Description

Analysed a compromised public-facing IIS server at TechNova Systems using a PCAP, memory image, and malware sample to reconstruct an attack spanning multiple tactics, including execution, persistence, stealth, and command and control.

Technical Writeups

As an aspiring SOC Analyst, I believe effective defense requires a deep understanding of offensive methodologies. This section contains comprehensive case studies and forensic reports detailing my approach to threat hunting, incident triage, and root-cause analysis. By deconstructing complex attacks—from legacy service exploits to advanced memory-resident rootkits—I demonstrate my practical ability to translate raw system telemetry into clear, actionable, and strategic threat intelligence.

Medium • Case Study

Memory-Driven Threat Hunting: Deconstructing EXIM4 and CVE-2010–4344

A deep-dive DFIR case study analyzing a sophisticated Linux intrusion. The approach utilized Volatility and Autopsy to correlate volatile memory artifacts with persistent disk logs, successfully uncovering an SSH brute-force smokescreen, an Exim4 RCE exploit, and a hidden rootkit deployment.

Medium • Case Study

DFIR Case Study: CyberDefenders Szechuan Sauce Lab

A comprehensive DFIR case study detailing the investigation of a compromised web environment. The approach involved parsing system logs, correlating threat actor lateral movement, extracting critical Indicators of Compromise (IoCs), and producing an actionable incident response timeline.

Medium • Investigation Report

Network Forensics Report: Packetmaze

A detailed network forensics investigation focusing on multi-protocol traffic analysis. The approach required deep-dive PCAP analysis to trace threat actor activity, decrypting network traffic, reconstructing malicious payloads, and identifying data exfiltration vectors across complex network layers.

Operational Capabilities

Technical Proficiencies

A comprehensive map of the specialized tools, platforms, and analytical frameworks I utilize to conduct deep-dive digital forensics, untangle network intrusions, and execute precise incident response workflows.

SIEM & Log Analysis

Aggregating, parsing, and correlating high-volume enterprise event telemetry across hybrid environments to detect unauthorized access, pinpoint anomalous behavioral patterns, and reconstruct granular end-to-end incident execution timelines during active operational triage workflows.

Splunk Elastic Stack (ELK) Windows Event Viewer Event Log Explorer Timeline Explorer

Endpoint & Artifact Forensics

Extracting critical forensic evidence from disk images, volatile memory dumps, Windows registry hives, jump lists, and mobile device backups using specialized forensic parsers to trace privilege escalation, uncover rootkits, and thoroughly evaluate persistent adversary footholds.

Volatility 3 Autopsy FTK Imager Registry Explorer RECmd LECmd JLECmd MFTECmd Timeline Explorer ALEAPP (Android) iLEAPP (iOS) RegRipper MFTDump HindSight

Network Forensics

Performing deep packet inspection and multi-protocol stream reassembly to intercept malicious payloads, trace adversary lateral movement, expose covert command-and-control beaconing patterns, and identify unauthorized data exfiltration channels across complex enterprise network layers.

Wireshark NetworkMiner Brim Snort (IDS) PCAP Triage TCP/IP Analysis

Threat Intelligence

Evaluating raw Indicators of Compromise (IoCs), profiling advanced persistent threat (APT) groups, and enriching suspicious endpoint telemetry against open-source intelligence databases to accurately attribute adversarial campaigns and produce actionable threat mitigation advisories.

VirusTotal Malpedia ThreatFox MalwareBazaar Red Canary Email Header Analyzer

Malware Triage

Executing controlled dynamic behavior analysis within automated sandboxes and leveraging static disassemblers, hex viewers, and string deobfuscators to unpack shellcode, analyze exploit scripts, and neutralize malicious multi-stage execution payloads across host operating systems.

ANY.RUN Libemu (Sctest) Scdbg HxD Strings CyberChef

Security Frameworks

Applying structured, industry-standard defensive methodologies and threat modeling frameworks to contextualize adversarial intrusion lifecycles, identify critical security posture gaps, and implement resilient defense-in-depth countermeasures across mission-critical organizational assets.

MITRE ATT&CK Cyber Kill Chain Unified Kill Chain Pyramid of Pain OWASP Top 10 Defense-in-Depth
Verified Credentials

Certifications

Industry-recognized blue team credentials, networking specializations, and forensic accreditations validating my expertise in security operations.

CIP Cyber May 2020

Computer Forensics Investigation

ID: Eh-12575
Verify ↗
Cisco Academy May 2020

Introduction to Cyber Security

Credential: Verified
Google Cloud Jul 2020

Introduction to Cloud Identity

ID: W2A7486PY9RW
Verify ↗
IBM Sep 2020

Cybersecurity Tools & Attacks

ID: P4DFJVE7NQWE
Verify ↗
Univ. of Maryland Sep 2020

Usable Security

ID: D3LX7UMZNSH3
Verify ↗
ISC2 Aug 2020

Networks & Communications Security

ID: ZHPZLYFL5WXU
Verify ↗
Google Aug 2020

Crash Course on Python

ID: FYGR5ZJFR5QZ
Verify ↗
DeepLearning.AI Sep 2020

Neural Networks & Deep Learning

ID: 3A82N2Z5CFWP
Verify ↗
Google Cloud Jul 2020

End-to-End ML with TensorFlow

ID: TQF58996HGVZ
Verify ↗
DeepLearning.AI Sep 2020

NLP with Classification & Vectors

ID: CQCYVD8VBADS
Verify ↗
IBM May 2020

Deep Learning with TensorFlow

ID: 757ac10766af
Verify ↗
← Scroll horizontally to explore all additional credentials →
Let’s connect

Have a role in mind?

I’m always open to discussing SOC Analyst opportunities, incident response challenges, and potential collaborations.