Triage, detection engineering, threat hunting, and incident response.
Eviction — APT28 Threat Hunting SOC Investigation
Completed
Threat hunting and SOC investigation lab focused on APT28 adversary behavior using the MITRE ATT&CK framework. Provides hands-on experience with detecting advanced persistent threats.
Threat HuntingAPT28MITRE ATT&CKSOC
Focus
Hypothesis-driven hunting across endpoint and network telemetry.
Mapped observed TTPs to MITRE ATT&CK techniques.
Produced an eviction plan and IOCs for containment.
An incident response lab simulating a phishing attack against a financial institution. Demonstrates threat intelligence gathering and SOC investigation techniques for financial fraud scenarios.
Triaged the phishing alert and analysed email headers, URLs, and attachments.
Gathered threat intelligence on attacker infrastructure and phishing indicators.
Pivoted on IOCs across SIEM and email gateway logs.
Documented findings and recommended user / control remediations.
Threat Simulation & Detection Engineering Lab
Completed
Hands-on cloud security and SOC-style lab covering malware detection, threat simulation, and detection engineering using the Pyramid of Pain and MITRE ATT&CK principles.
Detection EngineeringPurple TeamSIEMPyramid of PainMITRE ATT&CK
What I did
Ran controlled attack simulations and captured telemetry.
Authored and tuned detections to reduce false positives.
Validated detections against MITRE ATT&CK coverage.
Applied the Pyramid of Pain to prioritize resilient detection logic.
SOC Analyst Lab
Completed
Hands-on SOC simulation across four real-world threat scenarios — 100% case resolution, zero breaches.
SIEMPhishingMalware TriageSocial Engineering
Cases handled
Malware Triage — Investigated a quarantined Setup.exe from a suspicious freeware site, confirmed data stealer, prevented engineer execution.