Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
SOC-Analyst-Portfolio — A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research. | Kitploit
Ferramentas/GitHubGitHub/0x0allenace/soc-analyst-portfolio
Malware AnalysisDigital ForensicsThreat IntelligenceMachine LearningLearning & EducationIncident ResponseCurated ResourcesEmail SecurityAnomaly Detection

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Log Analysis
Labs & Practice
GitHub0x0allenace/soc-analyst-portfolio

SOC-Analyst-Portfolio

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity research.

Ver Repositório
16há 9 diasAinda não revisado
Compartilhar
Conteúdo não disponível no idioma solicitado. Mostrando versão em inglês.

Allen Ace Banner


🛡️ Allen Ace

SOC Analyst | Threat Hunter | Detection Engineer

Detect • Investigate • Respond • Defend

Welcome

This portfolio documents my hands-on cybersecurity journey through practical investigations, enterprise lab environments, detection engineering, digital forensics, malware analysis, threat hunting, and security analytics.

Each project demonstrates investigative methodology, security tooling, evidence correlation, detection development, and defensive thinking expected within a modern Security Operations Center (SOC).

Splunk Elastic Python Windows

MITRE ATT&CK Threat Hunting DFIR Digital Forensics Purple Team PowerShell

Table of Contents

  • About Me
  • Portfolio Highlights
  • Current Focus
  • Featured Projects
  • Technical Skills
  • Security Investigations
  • Malware Analysis
  • Email Security
  • Security Engineering
  • Security Tool Development
  • Detection Engineering
  • Certifications
  • Community
  • Cybersecurity Journey
  • Technical Articles
  • Video Walkthroughs
  • Portfolio Statistics
  • Contact

About Me

SOC Analyst with hands-on experience in Threat Hunting, Digital Forensics & Incident Response (DFIR), Detection Engineering, Malware Analysis, Security Analytics, and Python-based security tooling.

My work focuses on evidence-driven investigations, enterprise-style security monitoring, endpoint analysis, network analysis, malware investigations, memory forensics, and detection development aligned with the MITRE ATT&CK framework.

Portfolio Highlights

  • 10+ Enterprise-style Security Investigations
  • Purple Team Attack Simulation & Defensive Investigation
  • Static & Dynamic Malware Analysis
  • Memory Forensics with Volatility 3 & MemProcFS
  • Digital Forensics & Incident Response (DFIR)
  • Threat Hunting with Splunk & Elastic
  • Detection Engineering & SIEM Correlation
  • Network Traffic & PCAP Analysis
  • Security Analytics & Machine Learning
  • Python Security Automation
  • Technical Writing & Community Education

Current Focus

  • Detection Engineering
  • Threat Hunting
  • Purple Team Operations
  • Malware Analysis
  • Digital Forensics & Incident Response
  • Memory Forensics
  • Python Security Automation

Featured Projects


🔗 Connect

  • 🔗 LinkedIn
  • 💻 GitHub

Technical Skills

Security Investigations

Enterprise-style investigations demonstrating incident response, threat hunting, digital forensics, memory analysis, malware analysis, network forensics, and detection engineering.

Purple Team Simulation

Controlled adversary simulation followed by Blue Team detection, investigation, network forensics, and detection engineering.

Objective

Conduct a controlled PowerShell-based attack simulation within an isolated laboratory environment and evaluate whether endpoint and network telemetry could be used to detect, investigate, reconstruct, and respond to the attack.

Technologies

  • Elastic Security
  • Splunk
  • Sysmon
  • Wireshark
  • PowerShell
  • Kali Purple
  • Netcat
  • Python HTTP Server

Investigation Focus

  • PowerShell execution analysis
  • Windows process-tree reconstruction
  • Suspicious network activity
  • Reverse-shell detection
  • Network packet analysis
  • SIEM investigation
  • IOC identification
  • Timeline reconstruction
  • Detection engineering
  • Cross-tool evidence correlation

MITRE ATT&CK Mapping

Key Findings

  • Reconstructed the simulated attack chain from endpoint and network telemetry.
  • Identified suspicious PowerShell execution and process relationships.
  • Detected remote payload retrieval activity.
  • Identified and analyzed reverse-shell network communications.
  • Correlated Sysmon events with packet-level evidence.
  • Extracted host and network Indicators of Compromise.
  • Developed detection logic using both Elastic and Splunk.
  • Demonstrated the value of correlating endpoint, SIEM, and network evidence rather than relying on a single telemetry source.

📸 Evidence

Purple Team Investigation

SIEM Investigation

Network Analysis

🔗 Repository

Purple Team Simulation — PowerShell Reverse Shell Detection & Investigation

Lessons Learned

  • Strengthened purple team methodology by connecting adversary simulation with defensive investigation.
  • Improved PowerShell and Windows process analysis.
  • Strengthened SIEM investigation and detection engineering skills across Splunk and Elastic.
  • Improved network forensic analysis using Wireshark and PCAP evidence.
  • Reinforced evidence correlation across endpoint, SIEM, and network telemetry.

Memory Forensics Investigation

Evidence-driven Windows memory forensics investigation using Volatility 3 and MemProcFS to identify suspicious processes, injected code, anomalous memory regions, loaded modules, network artifacts, and Indicators of Compromise.

Objective

Analyze a captured Windows memory image to identify suspicious process activity, memory anomalies, injected code, loaded modules, network artifacts, and other evidence associated with potential compromise.

Technologies

  • Volatility 3
  • MemProcFS
  • FLARE-VM
  • Procmon
  • Windows
  • Memory Forensics
  • Digital Forensics

Investigation Focus

  • Process analysis
  • Suspicious memory regions
  • Code injection analysis
  • PE and memory artifact analysis
  • Loaded module investigation
  • Network artifact analysis
  • Cross-tool forensic correlation
  • Timeline reconstruction
  • IOC extraction
  • Evidence integrity

Methodology

The investigation followed an evidence-driven forensic workflow:

root@kitploit:~
Investigation Question
        ↓
Evidence Collection
        ↓
Artifact Identification
        ↓
Analysis
        ↓
Cross-Tool Correlation
        ↓
Finding
        ↓
IOC Extraction
        ↓
Detection / Response Opportunity

Key Findings

  • Investigated suspicious process activity within a captured Windows memory image.
  • Analyzed anomalous memory regions and potential injected code.
  • Examined loaded modules and PE-related memory artifacts.
  • Investigated network artifacts associated with suspicious processes.
  • Correlated Volatility 3 and MemProcFS findings.
  • Extracted host and network Indicators of Compromise.
  • Documented findings using an evidence-driven forensic methodology.
  • Maintained supporting evidence, timelines, analyst notes, and forensic artifacts.

Forensic Artifacts

The investigation includes:

  • Executive Summary
  • Technical Investigation Report
  • Analyst Notebook
  • Execution Timeline
  • Findings
  • Host IOCs
  • Network IOCs
  • Volatility 3 artifacts
  • MemProcFS artifacts
  • Evidence integrity documentation
  • Supporting screenshots

Evidence

Memory Analysis ProcMon

Malfind Memory Analysis

Volatility Pstree Tree Process Tree

🔗 Repository

Memory Forensics Investigation

Lessons Learned

  • Strengthened Windows memory forensics methodology.
  • Improved process and memory artifact analysis.
  • Strengthened cross-tool forensic correlation using Volatility 3 and MemProcFS.
  • Improved identification and documentation of forensic Indicators of Compromise.
  • Reinforced evidence-driven investigation and incident-response workflows.

Threat Hunting

Leveraging SIEM technologies to proactively identify, investigate, and respond to adversary behavior using real-world datasets and the MITRE ATT&CK framework.

Threat Hunting – Reconnaissance

Objective

Investigate reconnaissance activity within the BOTS v2 dataset using Splunk.

Technologies
  • Splunk
  • Windows Event Logs
  • MITRE ATT&CK
MITRE ATT&CK
TechniqueID
Active ScanningT1595
Gather Victim Network InformationT1590
Key Findings
  • Suspicious User-Agent identified
  • External IP pivot completed
  • IOC extraction performed
Screenshots

Threat Hunting Screenshot

Threat Hunting Screenshot

Threat Hunting Screenshot

🔗 Repository

Threat Hunting – Reconnaissance

Lessons Learned
  • Improved Splunk investigation methodology.
  • Reinforced ATT&CK mapping skills.
  • Strengthened IOC correlation workflow.
  • Enhanced understanding of enterprise SOC investigations.

Enterprise DFIR Lab

Objective

Simulate an enterprise incident response environment using Active Directory, pfSense, Velociraptor, and attacker emulation.

Technologies
  • Velociraptor
  • Active Directory
  • pfSense
  • Windows Event Logs
  • KAPE
  • Sysmon
MITRE ATT&CK Mapping
TechniqueID
Credential DumpingT1003
Remote ServicesT1021
Lateral Tool TransferT1570
Key Findings
  • Conducted enterprise-wide investigation.
  • Collected forensic artifacts.
  • Contained compromised hosts.
  • Documented incident response workflow.
📸 Screenshots

Enterprise Incident Response

Enterprise Incident Response

Enterprise Incident Response

🔗 Repository
  • Enterprise DFIR Lab
  • Velociraptor KAPE Forensic Triage
Lessons Learned
  • Improved Velociraptor artifact collection methodology.
  • Reinforced victim isolation methodology.
  • Strengthened IOC correlation workflow.
  • Enhanced understanding of enterprise SOC investigations.

Malware Analysis

Static and dynamic analysis of Windows malware samples to identify Indicators of Compromise, attacker techniques, malicious behaviors, and forensic artifacts using controlled malware analysis methodologies.

Static Malware Analysis Report

Objective

Perform static analysis on suspicious Windows PE files to identify malicious characteristics, extract Indicators of Compromise, and document findings using an enterprise-style malware analysis methodology.

Technologies

  • PEStudio
  • Detect It Easy (DIE)
  • FLOSS
  • Strings
  • VirusTotal
  • Hash Analysis
  • Windows PE Format

MITRE ATT&CK Mapping

TechniqueID
MasqueradingT1036
Obfuscated Files or InformationT1027

Key Findings

  • Identified suspicious PE characteristics.
  • Extracted file hashes and Indicators of Compromise.
  • Reviewed imported Windows API functions.
  • Analyzed embedded strings and metadata.
  • Documented suspicious behaviors without executing the samples.

📸 Screenshots

Static Malware Analysis

Static Malware Analysis

Static Malware Analysis

🔗 Repository

Static Malware Analysis Report

Lessons Learned

  • Strengthened Windows PE file analysis techniques.
  • Improved malware triage methodology using static analysis.
  • Reinforced IOC extraction and documentation workflows.
  • Enhanced understanding of executable structures and suspicious artifacts.

Windows Malware Behavioral Analysis

Objective

Analyze the runtime behavior of a Windows malware sample within a controlled malware analysis laboratory to identify malicious activities, persistence mechanisms, process behavior, network communications, and Indicators of Compromise.

Technologies

  • REMnux
  • FLARE VM
  • Procmon
  • Process Explorer
  • Wireshark
  • FakeNet-NG
  • Regshot
  • Sysmon
  • Windows Event Logs

Analysis Workflow

  • Initial malware triage
  • Process analysis
  • Registry monitoring
  • Filesystem monitoring
  • Network traffic analysis
  • IOC extraction
  • MITRE ATT&CK mapping

MITRE ATT&CK Mapping

Key Findings

  • Executed malware safely inside an isolated analysis environment.
  • Observed process creation and parent-child relationships.
  • Identified persistence mechanisms and registry modifications.
  • Analyzed filesystem activity and dropped artifacts.
  • Captured network communications and extracted Indicators of Compromise.
  • Documented behavioral findings using a structured malware analysis workflow.

📸 Screenshots

Process Tree

Procmon Activity

Regshot Comparison

FakeNet-NG Network Traffic

Wireshark Capture

🔗 Repository

Windows Malware Behavioral Analysis

Lessons Learned

  • Strengthened dynamic malware analysis methodology.
  • Improved behavioral IOC identification and correlation.
  • Reinforced process, registry, and network activity analysis.
  • Enhanced understanding of malware execution and persistence techniques.

Email Security

Investigation of phishing emails, malicious attachments, and email-based attack vectors.

Suspicious Email Attachment Analysis

Objective

Analyze suspicious email attachments within a controlled environment to determine malicious intent and identify Indicators of Compromise.

Technologies

  • VirusTotal
  • PE Studio
  • File Signature Analysis
  • Static Analysis

MITRE ATT&CK Mapping

TechniqueATT&CK ID
PhishingT1566
User ExecutionT1204

Key Findings

  • Verified true file type.
  • Examined embedded artifacts.
  • Assessed malicious behavior.
  • Documented findings.

📸 Screenshots

Email Attachment Analysis

Email Attachment Analysis

Email Attachment Analysis

🔗 Repository

Suspicious Email Attachment Analysis

Lessons Learned

  • Strengthened malware triage and static analysis techniques.
  • Improved identification and validation of Indicators of Compromise.
  • Reinforced understanding of phishing attack delivery mechanisms and malicious attachments.
  • Enhanced ability to correlate file artifacts with MITRE ATT&CK techniques during incident investigations.

Security Engineering

Building practical security tooling, detection content, and analytics that support enterprise security operations.

Security Analytics & Machine Learning

Applying machine learning techniques to improve behavioral threat detection and anomaly identification in enterprise environments.

Behavioral Anomaly Detection

Objective

Develop an unsupervised machine learning pipeline for identifying anomalous behavior within synthetic enterprise security logs.

Technologies
  • Python
  • Pandas
  • Scikit-learn
  • PyTorch
  • Jupyter Notebook
Models
  • Isolation Forest
  • Local Outlier Factor
  • One-Class SVM
  • Autoencoder
Key Findings
  • Generated synthetic enterprise log datasets.
  • Engineered behavioral security features.
  • Compared multiple anomaly detection algorithms.
  • Evaluated model performance using multiple visualizations.
📸 Screenshots

Security Anomaly Detection Screenshot

Security Anomaly Detection Screenshot

Security Anomaly Detection Screenshot

🔗 Repository

Behavioral Anomaly Detection

Lessons Learned
  • Improved feature engineering techniques for security event analysis.
  • Strengthened understanding of unsupervised machine learning models for anomaly detection.
  • Learned to evaluate and compare multiple detection algorithms using performance metrics and visualizations.
  • Enhanced ability to translate behavioral analytics into practical threat detection use cases.

Security Tool Development

Lightweight security utilities developed to automate common Blue Team and DFIR workflows.

File Signature Detector

Objective

Develop a Python-based file signature analyzer capable of detecting true file types using magic bytes.

Technologies

  • Python
  • Magic Bytes
  • Binary Analysis

Features

  • True file type detection
  • Malware triage support
  • Reverse engineering assistance
  • DFIR artifact validation

🔗 Repository

File Signature Detector

Lessons Learned

  • Improved understanding of file signature analysis for file type validation.
  • Reinforced Python programming skills through development of a practical security utility.
  • Strengthened malware triage techniques by identifying files based on their binary signatures.
  • Enhanced appreciation for file validation as a critical step in DFIR workflows.

Detection Engineering (Planned)

Designing and validating production-ready detections mapped to the MITRE ATT&CK® framework.

Planned Projects

  • Sigma Detection Library
  • Splunk Detection Rules (SPL)
  • Microsoft Sentinel Detection Rules (KQL)
  • Elastic Detection Rules
  • YARA Rules
  • Detection-as-Code
  • ATT&CK Coverage Matrix

Certifications

Currently pursuing industry-recognized cybersecurity certifications.

Planned

  • CompTIA Security+
  • Splunk Core Certified Power User
  • Elastic Certified Analyst
  • GIAC GCFA (Long-term)

Community

Sharing knowledge through technical writing, walkthroughs, and continuous learning.

My Cybersecurity Journey

2023

  • Began professional cybersecurity transition.
  • Worked on SOC operations and security monitoring.
  • Built foundational SIEM investigation skills.
  • Learned Splunk, Windows Event Logs, and detection workflows.

2024

  • Expanded threat hunting capabilities.
  • Investigated security incidents using enterprise-style datasets.
  • Developed DFIR workflows.
  • Started publishing technical research and walkthroughs.

2025

  • Advanced threat intelligence and incident investigation skills.
  • Built security automation tools using Python.
  • Developed enterprise lab environments.

2026

  • Expanded into purple team operations and detection validation.
  • Completed memory forensics investigations using Volatility 3 and MemProcFS.
  • Continued developing detection engineering capabilities.
  • Expanded malware analysis and DFIR portfolio.
  • Pursuing remote SOC, Threat Hunting, DFIR, and Detection Engineering opportunities.

Technical Articles

Featured Articles

  • Locking Down Against Bad USB: Detection and Defense Strategies
  • Wireshark: Getting to Know Wireshark
  • Discovering Security Weaknesses: A Practical Guide to Vulnerability Scanning
  • MemProcFS: The Game Changer in Memory Forensics
  • Static Malware Analysis of Suspicious Windows PE Samples: A Blue Team Investigation
  • Behavioral Malware Analysis: Investigating a Multi-Stage Malware Sample Inside an Isolated Lab
  • Memory Forensics Investigation Report
  • Purple Team Simulation: Detecting and Investigating a Simulated PowerShell Reverse Shell

View all articles → Medium

Video Walkthroughs

Latest Videos

  • Blue Team Detection Lab
  • Mythic C2 Lab (planned)
  • Purple Team Simulation (planned)
  • Memory Forensics Walkthrough (planned)
  • Threat Hunting (planned)
  • Active Directory Lab (planned)
  • Elastic SIEM (planned)
  • DFIR Walkthrough (planned)

Portfolio Statistics

Contact

  • 🔗 LinkedIn
  • 📖 Medium
  • 💻 GitHub
  • 🎥 YouTube
  • 🐦 X
  • 📧 Email: [email protected]

GitHub Statistics

GitHub Followers

Visitors

GitHub Stars

Let's Connect

I'm always interested in discussing:

  • Security Operations (SOC)
  • Threat Hunting
  • Detection Engineering
  • Purple Team Operations
  • Malware Analysis
  • Digital Forensics
  • Memory Forensics
  • Python Security Automation

Feel free to connect with me on LinkedIn or explore my repositories.

⭐ Thank You

Thank you for visiting my cybersecurity portfolio.

If you found these investigations useful, feel free to connect with me on LinkedIn, follow my work on Medium, or explore my repositories on GitHub.

I am always open to discussing cybersecurity, threat hunting, DFIR, detection engineering, and remote Security Operations opportunities.

Baixar ferramenta
ProjectFocus AreaRepository
Purple Team Simulation 01Attack Simulation / Detection EngineeringView
Memory Forensics InvestigationMemory Forensics / DFIRView
Threat Hunting – ReconnaissanceSplunk Threat HuntingView
Enterprise DFIR LabIncident ResponseView
Velociraptor Forensic TriageEndpoint ForensicsView
Suspicious Email Attachment AnalysisEmail SecurityView
Static Malware AnalysisMalware AnalysisView
Windows Malware Behavioral AnalysisDynamic Malware AnalysisView
Behavioral Anomaly DetectionMachine LearningView
File Signature DetectorPython Security ToolView
DomainTechnologies
SIEMSplunk, Elastic Security
Threat HuntingSPL, EQL, KQL/Search-based Investigation, MITRE ATT&CK
Detection EngineeringSigma, SPL, EQL, Behavioral Detection, Sequence Detection
DFIRVelociraptor, KAPE, Autopsy, FTK Imager
Memory ForensicsVolatility 3, MemProcFS
Malware AnalysisPEStudio, Detect It Easy, FLOSS, Procmon, Process Explorer
Network AnalysisWireshark, PCAP Analysis, TCP/IP
Endpoint SecuritySysmon, Windows Event Logs, Elastic Defend
Purple TeamAttack Simulation, Defensive Validation, Detection Validation
ProgrammingPython, PowerShell
InfrastructureActive Directory, pfSense, Windows
Evidence AnalysisIOC Extraction, Timeline Reconstruction, Process Analysis
TechniqueATT&CK ID
PowerShellT1059.001
Command and Scripting InterpreterT1059
Ingress Tool TransferT1105
System Owner/User DiscoveryT1033
System Information DiscoveryT1082
System Network Configuration DiscoveryT1016
Network Service ScanningT1046
TechniqueATT&CK ID
User ExecutionT1204
Command and Scripting InterpreterT1059
Process InjectionT1055
Registry Run Keys / Startup FolderT1547
File and Directory DiscoveryT1083
Application Layer ProtocolT1071
MetricValue
Security Investigations10+
Threat Hunting Investigations2+
DFIR Investigations3+
Malware Analysis Reports2
Purple Team Exercises1
Memory Forensics Investigations1
Machine Learning Projects1
Security Tools Developed1
Technical Articles Published80+
Video Walkthroughs5
MITRE ATT&CK Techniques Covered15+
LanguagesPython, PowerShell