
A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research.
Detect • Investigate • Respond • Defend
This portfolio documents my hands-on cybersecurity journey through practical investigations, enterprise lab environments, detection engineering, digital forensics, malware analysis, threat hunting, and security analytics.
Each project demonstrates investigative methodology, security tooling, evidence correlation, detection development, and defensive thinking expected within a modern Security Operations Center (SOC).
SOC Analyst with hands-on experience in Threat Hunting, Digital Forensics & Incident Response (DFIR), Detection Engineering, Malware Analysis, Security Analytics, and Python-based security tooling.
My work focuses on evidence-driven investigations, enterprise-style security monitoring, endpoint analysis, network analysis, malware investigations, memory forensics, and detection development aligned with the MITRE ATT&CK framework.
| Project | Focus Area | Repository |
|---|---|---|
| Purple Team Simulation 01 | Attack Simulation / Detection Engineering | View |
| Memory Forensics Investigation | Memory Forensics / DFIR | View |
| Threat Hunting – Reconnaissance | Splunk Threat Hunting | View |
| Enterprise DFIR Lab | Incident Response | View |
| Velociraptor Forensic Triage | Endpoint Forensics | View |
| Suspicious Email Attachment Analysis | Email Security | View |
| Static Malware Analysis | Malware Analysis | View |
| Windows Malware Behavioral Analysis | Dynamic Malware Analysis | View |
| Behavioral Anomaly Detection | Machine Learning | View |
| File Signature Detector | Python Security Tool | View |
| Domain | Technologies |
|---|---|
| SIEM | Splunk, Elastic Security |
| Threat Hunting | SPL, EQL, KQL/Search-based Investigation, MITRE ATT&CK |
| Detection Engineering | Sigma, SPL, EQL, Behavioral Detection, Sequence Detection |
| DFIR | Velociraptor, KAPE, Autopsy, FTK Imager |
| Memory Forensics | Volatility 3, MemProcFS |
| Malware Analysis | PEStudio, Detect It Easy, FLOSS, Procmon, Process Explorer |
| Network Analysis | Wireshark, PCAP Analysis, TCP/IP |
| Endpoint Security | Sysmon, Windows Event Logs, Elastic Defend |
| Purple Team | Attack Simulation, Defensive Validation, Detection Validation |
| Programming | Python, PowerShell |
| Infrastructure | Active Directory, pfSense, Windows |
| Evidence Analysis | IOC Extraction, Timeline Reconstruction, Process Analysis |
Enterprise-style investigations demonstrating incident response, threat hunting, digital forensics, memory analysis, malware analysis, network forensics, and detection engineering.
Controlled adversary simulation followed by Blue Team detection, investigation, network forensics, and detection engineering.
Conduct a controlled PowerShell-based attack simulation within an isolated laboratory environment and evaluate whether endpoint and network telemetry could be used to detect, investigate, reconstruct, and respond to the attack.
| Technique | ATT&CK ID |
|---|---|
| PowerShell | T1059.001 |
| Command and Scripting Interpreter | T1059 |
| Ingress Tool Transfer | T1105 |
| System Owner/User Discovery | T1033 |
| System Information Discovery | T1082 |
| System Network Configuration Discovery | T1016 |
| Network Service Scanning | T1046 |