All categories

// soc

SOC / Threat Detection Projects

Triage, detection engineering, threat hunting, and incident response.

Eviction — APT28 Threat Hunting SOC Investigation

Completed

Threat hunting and SOC investigation lab focused on APT28 adversary behavior using the MITRE ATT&CK framework. Provides hands-on experience with detecting advanced persistent threats.

Threat HuntingAPT28MITRE ATT&CKSOC

Focus

  • Hypothesis-driven hunting across endpoint and network telemetry.
  • Mapped observed TTPs to MITRE ATT&CK techniques.
  • Produced an eviction plan and IOCs for containment.

SOC Threat Intelligence Lab — SwiftSpend Financial Phishing Incident Investigation

Completed

An incident response lab simulating a phishing attack against a financial institution. Demonstrates threat intelligence gathering and SOC investigation techniques for financial fraud scenarios.

PhishingSOCThreat IntelligenceEmail AnalysisFinancial Fraud

What I did

  • Triaged the phishing alert and analysed email headers, URLs, and attachments.
  • Gathered threat intelligence on attacker infrastructure and phishing indicators.
  • Pivoted on IOCs across SIEM and email gateway logs.
  • Documented findings and recommended user / control remediations.

Threat Simulation & Detection Engineering Lab

Completed

Hands-on cloud security and SOC-style lab covering malware detection, threat simulation, and detection engineering using the Pyramid of Pain and MITRE ATT&CK principles.

Detection EngineeringPurple TeamSIEMPyramid of PainMITRE ATT&CK

What I did

  • Ran controlled attack simulations and captured telemetry.
  • Authored and tuned detections to reduce false positives.
  • Validated detections against MITRE ATT&CK coverage.
  • Applied the Pyramid of Pain to prioritize resilient detection logic.

SOC Analyst Lab

Completed

Hands-on SOC simulation across four real-world threat scenarios — 100% case resolution, zero breaches.

SIEMPhishingMalware TriageSocial Engineering

Cases handled

  • Malware Triage — Investigated a quarantined Setup.exe from a suspicious freeware site, confirmed data stealer, prevented engineer execution.
  • Phishing Email Analysis — Identified spear-phishing impersonating Stripe via typosquat domain; password-protected attachment confirmed malicious, targeting Finance Director.
  • Deepfake Vishing Attack — Detected social engineering via deepfake voice call impersonating CEO to trigger an off-hours password reset.
  • Credential Harvesting — Analyzed SIEM login anomalies, traced pre-login URLs to a fake Microsoft 365 portal, confirmed HR pharming.

Skills demonstrated

SIEM investigation, endpoint and malware analysis, phishing and domain verification, social engineering detection, log analysis, incident escalation.

Security Dashboard Lab

Completed

Investigated and responded to simulated enterprise incidents across Exchange, WordPress, Cisco and supply chain attack vectors.

Incident ResponseVulnerability MgmtHardening

What I did

  • Investigated incidents involving vulnerable Exchange servers, compromised WordPress sites, outdated Cisco firewalls, and suspected supply chain attacks.
  • Performed root cause analysis and selected remediations: patch management, password policy enforcement, malware mitigation, security hardening.
  • Applied SOC and IR concepts: triage, vulnerability management, endpoint monitoring, post-compromise investigation.

SOC Alert Lab

Completed

Triage workflows, alert reporting, and detection workbooks for network, PowerShell, and phishing alerts.

TriageSplunkMTTD/MTTA/MTTR

Outcomes

  • Effective SOC alert triage and proper reporting / escalation / communication.
  • Designed SOC workbooks for network, PowerShell, and mail phishing incidents.
  • Implemented MTTD, MTTA, MTTR with consideration for false-positive rate and acknowledgment delays.
  • Triaging phishing alerts with Splunk — identifying true positives with minimal investigation time.