Snort
Learn how to effectively use the Snort intrusion detection system to monitor network traffic for real-time threats, analyze captured traffic files, and accurately identify malicious anomalies.
A security-minded SOC Analyst trainee focused on strategic threat analysis, decisive incident response, and proactive risk awareness — combining disciplined investigation, critical thinking, and continuous improvement to strengthen organizational resilience.
I'm an entry-level SOC Analyst with a strong foundation in cybersecurity, built through certified coursework — including ISC2's Networks and Communications Security and Google's cybersecurity and cloud security fundamentals — combined with hands-on practice through simulated security labs. I've consistently developed my skills through platforms such as TryHackMe, where I ranked among the global top 3%, and CyberDefenders, achieving a global rank of 2,584 and a national rank of 155.
Beyond technical knowledge, I bring a security-first mindset built around analytical thinking, curiosity, attention to detail, disciplined investigation, clear communication, teamwork, adaptability, patience, and a commitment to continuous learning. As I begin my professional journey, my goal is to approach every security event with an open mind, understand the context behind it, and contribute thoughtfully to the team.
I believe credentials provide the foundation, but the way I think, learn, investigate, and grow tells the bigger story. Explore my certifications, hands-on experience, labs, and projects to get to know me better.
Operational security defense engineering, interactive portfolios, and tactical automation frameworks. Tap any project to explore full architectural details.
Rigorous simulation of enterprise security operations, real-world attack emulation, and blue team incident investigations across elite cybersecurity training platforms.
Engaged in comprehensive security operations paths focusing on continuous log monitoring, vulnerability identification, and defensive security hardening. Executed hands-on triage workflows across Linux and Windows lab architectures to detect unauthorized access.
Learn how to effectively use the Snort intrusion detection system to monitor network traffic for real-time threats, analyze captured traffic files, and accurately identify malicious anomalies.
Understand the core components of the Elastic Stack (ELK) and how Security Operations Center analysts leverage this powerful toolset to conduct comprehensive log investigations and threat hunting.
Explore the core concepts and underlying methodologies of Security Orchestration, Automation, and Response to streamline incident handling and improve overall security operations efficiency.
Understand the various techniques attackers use to map and discover assets within a target network, and learn the corresponding strategies to effectively detect this reconnaissance activity.
Discover the methods used by adversaries to extract sensitive information from a compromised network and learn how to proactively detect these data exfiltration attempts across multiple channels.
Learn the foundational concepts of analyzing network traffic using Wireshark, focusing on practical techniques to identify, investigate, and mitigate potential network anomalies and security threats.
Explore the various frameworks and extensive knowledge bases that MITRE provides to the cybersecurity community, learning how to leverage these resources to enhance threat intelligence and defensive postures.
Investigate the most common initial access techniques utilized by attackers targeting Windows environments, and learn the specific detection mechanisms required to identify these early-stage breaches.
Analyze the critical first steps threat actors take immediately following a successful Windows breach, learning how to detect early post-compromise activities and lateral movement indicators.
Examine the persistence mechanisms that threat actors deploy to maintain unauthorized access to compromised Windows hosts over extended periods, and learn how to identify these stealthy backdoors.
Explore the various vectors attackers use to compromise Linux systems, focusing on how to effectively monitor and detect these initial intrusion attempts by thoroughly analyzing system logs.
Investigate the immediate post-exploitation actions taken by attackers upon breaching a Linux server, learning practical techniques to detect early reconnaissance and privilege escalation attempts within the environment.
Understand the foundational steps and methodologies required to safely analyze and investigate suspected malware samples within a controlled environment.
Explore how Security Information and Event Management solutions aggregate and analyze system logs to effectively detect and investigate malicious network behavior.
Learn practical techniques for gathering and utilizing open-source threat intelligence to enrich your understanding and contextualization of suspicious IP addresses and domains.
Master the use of Splunk's search capabilities to efficiently triage security alerts, investigate potential threats, and pinpoint malicious activity within your infrastructure.
Examine the final stages of cyberattacks targeting Linux environments and learn how to accurately identify critical indicators of compromise embedded within system logs.
Develop essential skills to investigate security alerts using the Elastic Stack, comprehensively analyzing log data to effectively spot and respond to emerging threats.
Delve into the technical components that make up an email, learning how to dissect email headers and body content to identify sophisticated phishing attempts.
Gain an introduction to the core concepts of cyber threat intelligence, exploring relevant industry standards, essential frameworks, and the intelligence lifecycle.
Discover practical methodologies for enriching file and hash artifacts using various threat intelligence sources to quickly determine their potential maliciousness and scope.
Learn the key characteristics and defining features used to identify, classify, and deeply understand the behaviors of the most common malware types.
Understand how sophisticated adversaries leverage trusted, built-in Windows administrative tools to conduct stealthy attacks, and learn effective detection strategies to uncover them.
Understand the fundamental concept of the Pyramid of Pain framework, learning how it effectively categorizes and ranks threat indicators based on the level of difficulty they pose for adversaries to change.
Explore the Cyber Kill Chain framework, a critical model designed for identifying and preventing network intrusions by understanding the specific, sequential steps adversaries must take to achieve their malicious objectives.
Learn about the Unified Kill Chain framework, discovering how it establishes the distinct phases of a cyberattack and provides a structured methodology for identifying vulnerabilities and mitigating risks to IT assets.
Uncover hidden threats and persistent mechanisms operating within a compromised system, learning practical investigative techniques to effectively identify and evict malicious activity lurking beneath the surface.
Begin your journey into Windows environment monitoring by understanding key system logs, learning how to configure, collect, and analyze these logs effectively to proactively detect potential security threats.
Dive into the methodologies for detecting malicious web shells by conducting comprehensive analyses across multiple domains, including server logs, file system modifications, and anomalous network traffic patterns.
Familiarize yourself with the essential Linux log sources and understand their critical importance in security operations, learning how to effectively leverage them during routine SOC alert triage and incident investigations.
Gain a comprehensive understanding of various denial-of-service attack vectors, exploring practical detection techniques and implementing effective mitigation strategies to protect web infrastructure from disruptive DDoS campaigns.
Step into the role of a Junior Security Analyst to experience a typical day in the life, performing routine daily duties and understanding core operational workflows.
Master the usage of NetworkMiner for analyzing captured network traffic files, allowing you to practice essential network forensics activities and extract valuable network artifacts.
Gain a solid foundation in using Wireshark, covering the essential skills needed to navigate the interface, analyze various network protocols, and inspect PCAP files effectively.
Dive deeper into packet analysis fundamentals using Wireshark, learning advanced filtering and searching techniques to locate specific data and pinpoint the exact information you need.
Understand the techniques attackers use to enumerate system information and execute brute force attacks against various authentication mechanisms to test and validate system security.
Explore the core concepts of session management in web applications, detailing the different types of attacks that exploit insecure session implementations and how to prevent them.
Gain a deeper understanding of Security Operations Center (SOC) alerts, building a structured and systematic approach to efficiently analyze, prioritize, and triage incoming security events.
Discover and leverage useful corporate resources, such as workbooks and threat intelligence lookups, to help structure, streamline, and simplify the L1 alert triage process.
Explore the key performance metrics that drive the overall effectiveness of a Security Operations Center, and discover actionable strategies to continuously improve operations.
Understand the psychological and tactical reasons why humans are frequently targeted in cyber attacks, and explore how the SOC plays a crucial role in defending against social engineering.
Learn the methodologies attackers use to identify and exploit vulnerable or misconfigured computer systems, along with the defensive strategies required to secure and protect them.
Discover the various security roles within a Blue Team environment and chart a path for advancing your career in cybersecurity, starting from the foundational L1 analyst position.
Learn about the fundamental principles and key aspects of network security, including how to properly monitor network infrastructure and protect it against sophisticated adversaries.
Understand the core concepts of network analysis, exploring why it is an essential skill, how to properly collect network traffic, and a review of the various tools available.
Grasp the fundamental concepts of Security Information and Event Management systems, exploring their key features, core functionalities, and crucial role in centralizing security monitoring.
Gain a foundational understanding of Splunk, focusing on how SOC analysts utilize its powerful search and reporting capabilities to effectively investigate security logs and trace incidents.
Learn the essential principles behind Intrusion Detection Systems and gain practical, hands-on experience by working with Snort to monitor and evaluate suspicious network activity.
Explore the underlying mechanics of how the web functions, identify the most common website security vulnerabilities, and learn the essential protective measures required for a safer internet experience.
Dive into common web-based attacks and learn practical detection methodologies by thoroughly analyzing both web server logs and underlying network traffic for signs of compromise.
Understand the mechanics of Man-in-the-Middle (MITM) attacks and learn how to effectively analyze network traffic to identify the subtle footprints left behind by this type of interception.
Learn the foundational concepts of Endpoint Detection and Response solutions, exploring their core features, operational mechanics, and importance in securing individual host machines.
Delve into specific OWASP Top 10 vulnerabilities (A01, A07, and A09) and understand how these critical security risks relate directly to failures in applying the IAAA access control model.
Examine critical OWASP Top 10 categories (A02, A03, A06, and A10) to understand how fundamental application design flaws can introduce severe security risks and potential compromises.
Focused on a multi-layered digital forensics investigation—starting with email header analysis to trace the initial phishing vector, moving into endpoint artifact review to spot malicious invoice payloads, and finishing with network traffic inspection. The conclusion successfully mapped out the entire attack lifecycle, identifying how the threat actor infiltrated the environment, delivered the payload, and triggered outbound communication to fully resolve the incident.
Approach centered on thorough endpoint and log forensics—analyzing malicious spear-phishing artifacts, tracking script and process execution chains, and examining suspicious file payloads to trace the intrusion. The conclusion successfully mapped out the attacker's initial access vector, established how the payload was delivered and executed, and answered all forensic questions to fully close out the incident.
Systematically picking apart artifacts, tracking execution chains, and analyzing suspicious logs and files to reconstruct the attacker's methodology. Wrapping up the investigation brings a satisfying conclusion, successfully uncovering the intrusion vector, tracing lateral movement or persistence mechanisms, and answering all the key forensic questions to close out the case.
Analysed log preparations, tracking initial access vectors via malicious documents and stage-2 execution, and evaluating subsequent network traffic. The conclusion successfully mapped out internal reconnaissance, privilege escalation exploits, and the full extent of the compromise, answering all key forensic questions to trace the end-to-end incident.
Triaged incoming IDS/IPS alerts, inspecting packet captures or logs, and distinguishing between false positives and malicious activity. The conclusion successfully validated the network alert, tracked the source of the malicious traffic, and answered all core forensic questions to close out the security.
Analysed suspicious endpoint artifacts, tracking malicious process masquerading or execution flows, and examining system logs to trace the attacker's activity. The conclusion successfully uncovered the true nature of the anomalous process, mapped out the breach's footprint, and answered all key forensic questions to resolve the incident.
Conducted deep investigative analysis—diving into system files and forensic artifacts to untangle hidden anomalies and trace the attacker's footprint. The conclusion successfully unmasked the core threats, exposed the hidden secrets scattered across the environment, and answered all critical questions to fully resolve the case.
Focused on command and control (C2) traffic analysis—inspecting network packet captures, identifying beaconing patterns, and analyzing connection payloads to map out the adversary's communication infrastructure. The conclusion successfully exposed the active C2 server, traced the client-server interaction mechanisms, and answered all critical forensic questions to fully neutralize the threat vector.
The approach focused on email header triage and URL reputation analysis to dissect a coordinated phishing campaign. The conclusion successfully exposed the threat actor's infrastructure, mapped out malicious landing pages, and answered all forensic questions to neutralize the threat.
The approach centered on SIEM log analysis using Splunk—querying event logs, tracking user activity, and correlating historical endpoints. The conclusion successfully reconstructed the newcomer's anomalous footprint, pinpointed the exact point of compromise, and resolved the incident.
The approach focused on deep packet inspection and network traffic analysis in Wireshark—filtering streams, isolating suspicious protocol exchanges, and unearthing malicious payloads. The conclusion successfully decoded the attacker's network communications, identified the payload delivery mechanism, and closed out the investigation.
The approach involved hands-on email artifact examination—inspecting MIME structures, analyzing embedded attachments, and evaluating malicious links. The conclusion successfully classified the phishing vector, exposed the attacker's pretexting strategy, and answered all critical analytical questions.
The approach centered on defense-in-depth principles—reviewing email security controls like SPF, DKIM, and DMARC, alongside user awareness frameworks. The conclusion successfully established robust hardening strategies to mitigate future social engineering risks and secure organizational boundaries.
The approach dove deeper into advanced Windows forensics—analyzing registry hives, event logs, and persistent artifacts left behind by an ongoing intrusion. The conclusion successfully mapped out the attacker's advanced persistence and lateral movement tactics, delivering a comprehensive incident report.
Targeted blue team labs focusing on digital forensics, artifact extraction, and post-compromise analysis.
Learned endpoint forensics by analyzing webserver honeypot logs to detect attacker techniques—including execution, persistence, defense impairment, credential access, and discovery—using Linux command-line tools, grep, and text editors.
Investigated a brute-force attack and persistence using Volatility with a custom Debian profile. Used Autopsy and FTK Imager for memory dump analysis, uncovering unauthorized outbound connections and malicious payloads.
Investigated a Windows VM image using FTK Imager, Registry Explorer, RegRipper, HxD, DB Browser, HindSight, Event Log Explorer, and MFTDump.
Analysed with uncompressing the lab archive—using the password cyberdefenders.org—and analyzing a diverse set of forensic artifacts. These include EnCase disk images (.E01 to .E04), memory dumps (.mem), packet captures (.pcap), and CSV logs to investigate techniques across initial access, execution, persistence, privilege escalation, and stealth.
Centered around a user who thought they were downloading the legitimate Sysinternals suite, only to find the files unresponsive and their machine progressively slowing down. Diving into the artifacts using tools like Registry Explorer, Event Log Explorer, and Autopsy, I had to piece together the attacker's tactics—focusing heavily on Execution, Command And Control, and Impact. It’s a great, medium-difficulty hands-on case that really sharpens your malware triage and artifact analysis skills.
Tackling the KrakenKeylogger Lab was an engaging dive into endpoint forensics that really put my investigative skills to the test. Uncovering how an insider threat attempted extortion by locking away a completed assignment required meticulously piecing together the timeline and analyzing techniques spanning initial access, persistence, and exfiltration. Utilizing tools like DB Browser For SQLite, LECmd, and Timeline Explorer made it deeply rewarding to trace the threat actor's steps and ultimately crack the case
Analysed Windows mail artifacts like Microsoft HxStore.hxd files and employing essential tools such as FTK Imager, SQLite Viewer, Strings, and CyberChef to decode files, extract crucial intel, and uncover the execution tactics behind the cyber attack.
Investigated the Linux disk image of the malicious employee Karen, you navigated through crucial endpoint forensics techniques—focusing on execution and credential access tactics with tools like FTK Imager. Uncovering the internal illegal activities within TAAUSAI made for a compelling and rewarding challenge, showcasing sharp investigative skills and solid blue team capabilities.
Tackling The Crime Lab on CyberDefenders was an engaging exercise in mobile endpoint forensics. Stepping into a murder investigation using the victim's recovered smartphone, I utilized tools like ALEAPP and DB Browser for SQLite to meticulously comb through digital artifacts. By correlating witness statements with data extracted from the device, I successfully traced the timeline of events, pieced together the crucial clues leading up to the incident, and solved the case.
Successfully dissected a compromised memory dump to trace the attacker's footsteps, uncover privilege escalation and stealth tactics, and analyze command and control channels. This challenge sharpened my ability to identify specific malware families, understand how NIDS bypass techniques work, and effectively uncover forensic artifacts left behind during an intrusion.
Investigative process involved deep-diving into an endpoint memory dump to trace a sophisticated malware intrusion. Utilizing essential blue team tools like Volatility 3 and VirusTotal, the analysis focused on uncovering suspicious workstation behavior, tracking the malicious actions of the Ramnit infection, and successfully extracting key forensic findings to solve the challenge.
used Volatility 3 to dive deep into the memory dump from the compromised financial workstation. By carefully tracing anomalies tied to stealth and discovery tactics, I was able to piece together the attacker's footprint, uncover the breach's origin, and successfully assess the full scope of the incident.
Focuses on key tactics such as Execution, Persistence, Privilege Escalation, Command and Control, and Impact, while utilizing tools like Malpedia, VirusTotal, ANY.RUN, Email Header Analyzer, and MalwareURL to analyze artifacts and uncover information about the attacker.
Revolved around an IT security check at GlobalTech Industries, where abnormal network traffic and employee search queries being redirected to unfamiliar websites prompted a deeper investigation into Initial Access and Execution tactics using tools like VirusTotal and Red Canary.
Centered around a phishing incident. An accountant received an email titled "Urgent New Order" with an attached malicious invoice containing false information, which subsequently triggered SIEM alerts for a suspicious file download linked to a PowerPoint file.
Analysed and examined the provided indicators and attack methods to track the threat actor's infrastructure and uncover how credentials were stolen and funds were exfiltrated.
Analysed the malware's hash using tools like Whois, VirusTotal, MalwareBazaar, ThreatFox, and ANY.RUN to gather actionable intelligence across tactics such as Execution, Persistence, Privilege Escalation, Stealth, Defence Impairment, Discovery, Collection, and Impact to support the Incident Response team.
Examined indicators and monitor the activities of this advanced persistent threat (APT) group using analysis tools such as VirusTotal, Malpedia, Tria.Ge, and ANY.RUN.
Conducted deep packet inspection using Wireshark and Network Miner to decrypt traffic, extract malicious payloads, and trace exfiltration paths across complex network layers.
Learned PCAP analysis of honeypot interactions and automatic exploitation using Brim, Wireshark, NetworkMiner, Libemu (Sctest), Scdbg, and IP LookUp.
Analysed a corporate ransomware security incident to uncover attacker tactics—such as execution, persistence, and impact—using tools like Wireshark, Network Miner, and Windows Event Viewer.
Investigated a simulated security incident where an accountant received a suspicious invoice email containing a download link, leading to malicious network traffic, command-and-control activity, and data exfiltration.
Analysed a PCAP file to investigate the compromise of an Apache Tomcat web server within a company's intranet and identifying malicious activities spanning several MITRE ATT&CK tactics using tools like Wireshark and NetworkMiner.
The investigation focused on analyzing a PCAP file using Wireshark to trace suspicious lateral movement activity involving PsExec flagged by an Intrusion Detection System (IDS).
Network forensics challenge focuses on tactics such as Initial Access, Persistence, and Command and Control using tools like Wireshark and Network Miner.
Analysed a PCAP file from a compromised machine exhibiting suspicious network traffic to determine the attack method, identify malicious payloads, and trace the timeline of events.
Analysed a compromised public-facing IIS server at TechNova Systems using a PCAP, memory image, and malware sample to reconstruct an attack spanning multiple tactics, including execution, persistence, stealth, and command and control.
As an aspiring SOC Analyst, I believe effective defense requires a deep understanding of offensive methodologies. This section contains comprehensive case studies and forensic reports detailing my approach to threat hunting, incident triage, and root-cause analysis. By deconstructing complex attacks—from legacy service exploits to advanced memory-resident rootkits—I demonstrate my practical ability to translate raw system telemetry into clear, actionable, and strategic threat intelligence.
A deep-dive DFIR case study analyzing a sophisticated Linux intrusion. The approach utilized Volatility and Autopsy to correlate volatile memory artifacts with persistent disk logs, successfully uncovering an SSH brute-force smokescreen, an Exim4 RCE exploit, and a hidden rootkit deployment.
A comprehensive DFIR case study detailing the investigation of a compromised web environment. The approach involved parsing system logs, correlating threat actor lateral movement, extracting critical Indicators of Compromise (IoCs), and producing an actionable incident response timeline.
A detailed network forensics investigation focusing on multi-protocol traffic analysis. The approach required deep-dive PCAP analysis to trace threat actor activity, decrypting network traffic, reconstructing malicious payloads, and identifying data exfiltration vectors across complex network layers.
A comprehensive map of the specialized tools, platforms, and analytical frameworks I utilize to conduct deep-dive digital forensics, untangle network intrusions, and execute precise incident response workflows.
Aggregating, parsing, and correlating high-volume enterprise event telemetry across hybrid environments to detect unauthorized access, pinpoint anomalous behavioral patterns, and reconstruct granular end-to-end incident execution timelines during active operational triage workflows.
Extracting critical forensic evidence from disk images, volatile memory dumps, Windows registry hives, jump lists, and mobile device backups using specialized forensic parsers to trace privilege escalation, uncover rootkits, and thoroughly evaluate persistent adversary footholds.
Performing deep packet inspection and multi-protocol stream reassembly to intercept malicious payloads, trace adversary lateral movement, expose covert command-and-control beaconing patterns, and identify unauthorized data exfiltration channels across complex enterprise network layers.
Evaluating raw Indicators of Compromise (IoCs), profiling advanced persistent threat (APT) groups, and enriching suspicious endpoint telemetry against open-source intelligence databases to accurately attribute adversarial campaigns and produce actionable threat mitigation advisories.
Executing controlled dynamic behavior analysis within automated sandboxes and leveraging static disassemblers, hex viewers, and string deobfuscators to unpack shellcode, analyze exploit scripts, and neutralize malicious multi-stage execution payloads across host operating systems.
Applying structured, industry-standard defensive methodologies and threat modeling frameworks to contextualize adversarial intrusion lifecycles, identify critical security posture gaps, and implement resilient defense-in-depth countermeasures across mission-critical organizational assets.
Industry-recognized blue team credentials, networking specializations, and forensic accreditations validating my expertise in security operations.
I’m always open to discussing SOC Analyst opportunities, incident response challenges, and potential collaborations.