Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SOC-Analyst-Portfolio — A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research. | Kitploit
Tools/GitHubGitHub/0x0allenace/soc-analyst-portfolio
Malware AnalysisDigital ForensicsThreat IntelligenceMachine LearningLearning & EducationIncident ResponseCurated ResourcesEmail SecurityAnomaly Detection

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Log Analysis
Labs & Practice
GitHub0x0allenace/soc-analyst-portfolio

SOC-Analyst-Portfolio

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research.

View Repository
112 days agoNot yet reviewed

Allen Ace Banner


🛡️ Allen Ace

SOC Analyst | Threat Hunter | Detection Engineer

Detect • Investigate • Respond • Defend

Welcome

This portfolio documents my hands-on cybersecurity journey through practical investigations, enterprise lab environments, detection engineering, digital forensics, and security analytics.

Each project is designed to demonstrate the investigative methodology, tooling, and defensive thinking expected within a modern Security Operations Center (SOC).

Splunk Elastic Python Windows

MITRE ATT&CK Threat Hunting DFIR Digital Forensics Active Directory PowerShell

📚 Table of Contents

  • About Me
  • Technical Skills
  • Investigations
  • Threat Hunting
  • Malware Analysis
  • Email Security
  • Engineering
  • Security Analytics & Machine Learning
  • Security Tool Development
  • Detection Engineering
  • Community
  • Cybersecurity Journey
  • Technical Articles
  • Video Walkthroughs
  • Portfolio Statistics
  • Contact

👋 About Me

SOC Analyst with hands-on experience in Threat Hunting, Digital Forensics & Incident Response (DFIR), Detection Engineering, Security Analytics, and Python-based security tooling. My work focuses on enterprise-style investigations aligned with the MITRE ATT&CK framework.

Portfolio Highlights

  • 8+ Enterprise Security Investigations
  • Static & Dynamic Malware Analysis
  • Digital Forensics & Incident Response (DFIR)
  • Threat Hunting with Splunk & Elastic
  • Security Analytics & Machine Learning
  • Python Security Automation
  • Technical Writing & Community Education

🎯 Current Focus

  • Detection Engineering
  • Threat Hunting
  • Malware Analysis
  • Digital Forensics (DFIR)
  • Python Security Automation

⭐ Featured Projects


🔗 Connect

  • 🔗 LinkedIn
  • 💻 GitHub

🛠️ Technical Skills

🛡️ Security Investigations

Enterprise-style investigations demonstrating real-world incident response, threat hunting, and forensic analysis.

🔎 Threat Hunting

Leveraging SIEM technologies to proactively identify, investigate, and respond to adversary behavior using real-world datasets and the MITRE ATT&CK framework.

Threat Hunting – Reconnaissance

Objective

Investigate reconnaissance activity within the BOTS v2 dataset using Splunk.

Technologies

  • Splunk
  • Windows Event Logs
  • MITRE ATT&CK

MITRE ATT&CK

TechniqueID
Active ScanningT1595
Gather Victim Network InformationT1590

Key Findings

  • Suspicious User-Agent identified
  • External IP pivot completed
  • IOC extraction performed

Screenshots

Threat Hunting Screenshot

Threat Hunting Screenshot

Threat Hunting Screenshot

🔗 Repository: View Project

💡 Lessons Learned

  • Improved Splunk investigation methodology.
  • Reinforced ATT&CK mapping skills.
  • Strengthened IOC correlation workflow.
  • Enhanced understanding of enterprise SOC investigations.

📌 Enterprise DFIR Lab

🎯 Objective

Simulate an enterprise incident response environment using Active Directory, pfSense, Velociraptor, and attacker emulation.

🛠️ Technologies

  • Velociraptor
  • Active Directory
  • pfSense
  • Windows Event Logs
  • KAPE
  • Sysmon

🎯 MITRE ATT&CK Mapping

TechniqueID
Credential DumpingT1003
Remote ServicesT1021
Lateral Tool TransferT1570

🔍 Key Findings

  • Conducted enterprise-wide investigation.
  • Collected forensic artifacts.
  • Contained compromised hosts.
  • Documented incident response workflow.

📸 Screenshots

Enterprise Incident Response Enterprise Incident Response Enterprise Incident Response

🔗 Repository

  • Enterprise DFIR Lab
  • Velociraptor KAPE Forensic Triage

💡 Lessons Learned

  • Improved Velociraptor Artifact collection methodology.
  • Reinforced victim isolation methodology.
  • Strengthened IOC correlation workflow.
  • Enhanced understanding of enterprise SOC investigations.

🚧 Coming Soon

  • Memory Forensics
  • Registry Forensics
  • Disk Forensics
  • Windows Artifact Analysis
  • Timeline Analysis
  • KAPE Forensic Triage
  • Volatility Memory Analysis

🦠 Malware Analysis

Static and dynamic analysis of Windows malware samples to identify Indicators of Compromise (IOCs), attacker techniques, malicious behaviors, and forensic artifacts using enterprise-style malware analysis methodologies.


📌 Static Malware Analysis Report

🎯 Objective

Perform static analysis on suspicious Windows PE files to identify malicious characteristics, extract Indicators of Compromise (IOCs), and document findings using an enterprise-style malware analysis methodology.

🛠️ Technologies

  • PEStudio
  • Detect It Easy (DIE)
  • FLOSS
  • Strings
  • VirusTotal
  • Hash Analysis
  • Windows PE Format

🎯 MITRE ATT&CK Mapping

TechniqueID
MalwareT1587
MasqueradingT1036
Obfuscated Files or InformationT1027

🔍 Key Findings

  • Identified suspicious PE characteristics.
  • Extracted file hashes and Indicators of Compromise.
  • Reviewed imported Windows API functions.
  • Analyzed embedded strings and metadata.
  • Documented suspicious behaviors without executing the samples.

📸 Screenshots

Static Malware Analysis

Static Malware Analysis

Static Malware Analysis

🔗 Repository: Static Malware Analysis Report

💡 Lessons Learned

  • Strengthened Windows PE file analysis techniques.
  • Improved malware triage methodology using static analysis.
  • Reinforced IOC extraction and documentation workflows.
  • Enhanced understanding of executable structures and suspicious artifacts.

📌 Windows Malware Behavioral Analysis

🎯 Objective

Analyze the runtime behavior of a Windows malware sample within a controlled malware analysis laboratory to identify malicious activities, persistence mechanisms, process behavior, network communications, and Indicators of Compromise (IOCs).


🛠️ Technologies

  • REMnux
  • FLARE VM
  • Procmon
  • Process Explorer
  • Wireshark
  • FakeNet-NG
  • Regshot
  • Sysmon
  • Windows Event Logs

🔄 Analysis Workflow

  • Initial malware triage
  • Process analysis
  • Registry monitoring
  • Filesystem monitoring
  • Network traffic analysis
  • IOC extraction
  • MITRE ATT&CK mapping

🎯 MITRE ATT&CK Mapping


🔍 Key Findings

  • Executed malware safely inside an isolated analysis environment.

  • Observed process creation and parent-child relationships.

  • Identified persistence mechanisms and registry modifications.

  • Analyzed filesystem activity and dropped artifacts.

  • Captured network communications and extracted Indicators of Compromise.

  • Documented behavioral findings using an enterprise malware analysis workflow.


📸 Screenshots

Process Tree

Procmon Activity

Regshot Comparison

FakeNet-NG Network Traffic

Wireshark Capture

🔗 Repository

Windows Malware Behavioral Analysis


💡 Lessons Learned

  • Strengthened dynamic malware analysis methodology.
  • Improved behavioral IOC identification and correlation.
  • Reinforced process, registry, and network activity analysis.
  • Enhanced understanding of malware execution and persistence techniques.

📧 Email Security

Investigation of phishing emails, malicious attachments, and email-based attack vectors.

📌 Suspicious Email Attachment Analysis

🎯 Objective

Analyze suspicious email attachments within a controlled environment to determine malicious intent and identify Indicators of Compromise.

🛠️ Technologies

  • VirusTotal
  • PE Studio
  • File Signature Analysis
  • Static Analysis

🎯 MITRE ATT&CK Mapping

TechniqueATT&CK ID
PhishingT1566
User ExecutionT1204

🔍 Key Findings

  • Verified true file type.
  • Examined embedded artifacts.
  • Assessed malicious behavior.
  • Documented findings.

📸 Screenshots

Email Attachment Analysis Email Attachment Analysis Email Attachment Analysis

🔗 Repository: View Project

💡 Lessons Learned

  • Strengthened malware triage and static analysis techniques.
  • Improved identification and validation of Indicators of Compromise (IOCs).
  • Reinforced understanding of phishing attack delivery mechanisms and malicious attachments.
  • Enhanced the ability to correlate file artifacts with MITRE ATT&CK techniques during incident investigations.

🚧 Coming Soon

  • Email Header Analysis
  • Email Body Analysis
  • Business Email Compromise Investigation
  • SPF / DKIM / DMARC Validation
  • Email IOC Extraction

⚙️ Security Engineering

Building practical security tooling, detection content, and analytics that support enterprise security operations.

🤖 Security Analytics & Machine Learning

Applying machine learning techniques to improve behavioral threat detection and anomaly identification in enterprise environments.

📌 Behavioral Anomaly Detection

🎯 Objective

Develop an unsupervised machine learning pipeline for identifying anomalous behavior within synthetic enterprise security logs.

🛠️ Technologies

  • Python
  • Pandas
  • Scikit-learn
  • PyTorch
  • Jupyter Notebook

🤖 Models

  • Isolation Forest
  • Local Outlier Factor
  • One-Class SVM
  • Autoencoder

🔍 Key Findings

  • Generated synthetic enterprise log datasets.
  • Engineered behavioral security features.
  • Compared multiple anomaly detection algorithms.
  • Evaluated model performance using multiple visualizations.

📸 Screenshots

Security Anomaly Detection Screenshot

Security Anomaly Detection Screenshot

Security Anomaly Detection Screenshot

🔗 Repository: View Project

💡 Lessons Learned

  • Improved feature engineering techniques for security event analysis.
  • Strengthened understanding of unsupervised machine learning models for anomaly detection.
  • Learned to evaluate and compare multiple detection algorithms using performance metrics and visualizations.
  • Enhanced the ability to translate behavioral analytics into practical threat detection use cases.

🚧 Coming Soon

  • User & Entity Behavior Analytics (UEBA)
  • Insider Threat Detection
  • Time-Series Threat Detection
  • Explainable AI for Security
  • Graph-Based Threat Analytics

🛠️ Security Tool Development

Lightweight security utilities developed to automate common Blue Team and DFIR workflows. These tools demonstrate practical scripting ability applied to real security operations challenges.

📌 File Signature Detector

🎯 Objective

Develop a Python-based file signature analyzer capable of detecting true file types using magic bytes.

🛠️ Technologies

  • Python
  • Magic Bytes
  • Binary Analysis

⚙️ Features

  • True file type detection
  • Malware triage support
  • Reverse engineering assistance
  • DFIR artifact validation

🔗 Repository: View Project

💡 Lessons Learned

  • Improved understanding of file signature (magic byte) analysis for file type validation.
  • Reinforced Python programming skills through the development of a practical security utility.
  • Strengthened malware triage techniques by identifying files based on their true binary signatures.
  • Enhanced appreciation for file validation as a critical step in digital forensics and incident response workflows.

🚧 Coming Soon

  • IOC Extractor
  • IOC Enrichment Tool
  • Log Parser
  • Hash Analyzer
  • Threat Intelligence Aggregator
  • Detection Rule Generator

⚙️ Detection Engineering (Planned)

Designing and validating production-ready detections mapped to the MITRE ATT&CK® framework.

📚 Planned Projects

  • Sigma Detection Library
  • Splunk Detection Rules (SPL)
  • Microsoft Sentinel Detection Rules (KQL)
  • Elastic Detection Rules
  • YARA Rules
  • Detection-as-Code
  • ATT&CK Coverage Matrix

📜 Certifications

Currently pursuing industry-recognized cybersecurity certifications.

Planned

  • CompTIA Security+
  • Splunk Core Certified Power User
  • Elastic Certified Analyst
  • GIAC GCFA (Long-term)

🌐 Community

Sharing knowledge through technical writing, walkthroughs, and continuous learning.

🗺️ My Cybersecurity Journey

2023

  • Began professional cybersecurity transition.
  • Worked on SOC operations and security monitoring.
  • Built foundational SIEM investigation skills.
  • Learned Splunk, Windows Event Logs, and detection workflows.

2024

  • Expanded threat hunting capabilities.
  • Investigated security incidents using enterprise-style datasets.
  • Developed DFIR workflows.
  • Started publishing technical research and walkthroughs.

2025

  • Advanced threat intelligence and incident investigation skills.
  • Built security automation tools using Python.
  • Developed enterprise lab environments.

2026

  • Building a detection engineering portfolio.
  • Expanding SIEM detection capabilities.
  • Pursuing remote SOC and Threat Hunting opportunities.

📝 Technical Articles

📝 Featured Articles

  • Locking Down Against Bad USB: Detection and Defense Strategies
  • Wireshark: Getting to Know Wireshark
  • Discovering Security Weaknesses: A Practical Guide to Vulnerability Scanning
  • MemProcFS: The Game Changer in Memory Forensics
  • Static Malware Analysis of Suspicious Windows PE Samples: A Blue Team Investigation
  • Behavioral Malware Analysis: Investigating a Multi-Stage Malware Sample Inside an Isolated Lab
  • Detection Engineering (planned) View all articles → Medium

🎥 Video Walkthroughs

Latest Videos

  • Blue Team Detection Lab
  • Mythic C2 Lab (planned)
  • Threat Hunting (planned)
  • Active Directory Lab (planned)
  • Elastic SIEM (planned)
  • DFIR Walkthrough (planned)

📊 Portfolio Statistics

📫 Contact

  • 🔗 LinkedIn
  • 📖 Medium
  • 💻 GitHub
  • 🎥 YouTube
  • 🐦 X
  • 📧 Email: [email protected]

📈 GitHub Statistics

GitHub Followers Visitors GitHub Stars

🤝 Let's Connect

I'm always interested in discussing:

  • Security Operations (SOC)
  • Threat Hunting
  • Detection Engineering
  • Malware Analysis
  • Digital Forensics
  • Python Security Automation

Feel free to connect with me on LinkedIn or explore my repositories.

⭐ Thank You

Thank you for visiting my cybersecurity portfolio.

If you found these investigations useful, feel free to connect with me on LinkedIn, follow my work on Medium, or explore my repositories on GitHub.

I am always open to discussing cybersecurity, threat hunting, DFIR, and remote Security Operations opportunities.

Download Tool
ProjectFocus AreaRepository
Threat Hunting – ReconnaissanceSplunk Threat HuntingView
Enterprise DFIR LabIncident ResponseView
Velociraptor Forensic TriageEndpoint ForensicsView
Suspicious Email Attachment AnalysisEmail SecurityView
Static Malware AnalysisMalware AnalysisView
Windows Malware Behavioral AnalysisDynamic Malware AnalysisView
Behavioral Anomaly DetectionMachine LearningView
File Signature DetectorPython Security ToolView
DomainTechnologies
SIEMSplunk, Elastic
Threat HuntingSPL, MITRE ATT&CK
DFIRVelociraptor, KAPE, Autopsy, FTK Imager
Malware AnalysisPEStudio, Detect It Easy, FLOSS, Procmon, Wireshark
Detection EngineeringSigma, SPL
Endpoint SecuritySysmon, Windows Event Logs
ProgrammingPython, PowerShell
NetworkingWireshark, TCP/IP
InfrastructureActive Directory, pfSense
TechniqueATT&CK ID
User ExecutionT1204
Command and Scripting InterpreterT1059
Process InjectionT1055
Registry Run Keys / Startup FolderT1547
File and Directory DiscoveryT1083
Application Layer ProtocolT1071
MetricValue
Security Investigations8+
Threat Hunting Investigations2
DFIR Investigations2
Malware Analysis Reports2
Machine Learning Projects1
Security Tools Developed1
Technical Articles Published70+
Video Walkthroughs5
MITRE ATT&CK Techniques Covered12+
LanguagesPython, PowerShell