SOC Investigation: HTTP Cookie Data Exfiltration
Scenario Platform: TryHackMe Role: SOC Analyst / Network Forensics Investigator Objective: Analyze a provided packet capture for a covert communication channel, identify where exfiltrated data was...
Scenario Platform: TryHackMe Role: SOC Analyst / Network Forensics Investigator Objective: Analyze a provided packet capture for a covert communication channel, identify where exfiltrated data was...
Objective The goal of this project was to build an isolated security-operations lab that centralizes endpoint and network telemetry for repeatable detection and investigation exercises. The valida...
Scenario Platform: TryHackMe (Room: Warzone 1) Role: Tier 1 SOC Analyst Objective: Triage a high-priority IDS alert by analyzing a provided packet capture (Zone1.pcap) to confirm Command and Contr...
In the SANS SEC504 course, I conducted a full-scope investigation into a simulated ransomware attack by the “Midnite Meerkats” threat group. This series of labs required pivoting from live system a...
Scope Quick-reference event IDs used regularly in SOC triage and investigation workflows. Event ID 4688 - Process Creation Use to confirm process execution details: Process name Command-li...
Purpose Standardize Tier 1 triage for suspicious PowerShell alerts in lab and simulation workflows. Required Data EDR or endpoint process telemetry Windows Security logs (Event ID 4688) A...
Alert Summary Initial investigation began with one suspected infected endpoint in a ransomware simulation. Evidence Observed Repeated outbound traffic with consistent interval behavior Beac...
Alert Summary Detection triggered for suspicious PowerShell execution on host WIN-01 under user jsmith. Evidence Observed Event ID 4688 – Process creation Command line included base64-encod...
In the SANS SEC504 course, I targeted the “Falsimentis Customer Support” portal to identify and exploit common web vulnerabilities found in the OWASP Top 10. Here is the step-by-step methodology I...
In the SANS SEC504 course, I explored the techniques used to capture and crack credentials. Credentials are the keys to the kingdom; acquiring them allows an attacker to bypass sophisticated exploi...