WhatsApp ยท Quick response

๐ŸŒ Open to Remote SOC Roles  ยท  AU ยท CA ยท US ยท NZ ยท UAE

Hire Me
HomeAboutSOC Projects PortfolioServicesAcademy CertificationsCAI Initiative BlogContact โ†’
Active Investigations & Published Builds

SOC & DFIR Investigations

Real-world cybersecurity investigations documented using professional DFIR methodology. Each case includes full scenario, MITRE ATT&CK mapping, IOCs, detection strategy, and analyst reasoning.

8
Published Cases
1
ICDFA Published
๐Ÿ†
RTL Award Won
18+
IOCs Documented
Cybersecurity Investigations

SOC & DFIR Cases

๐Ÿ”ด TLP:WHITESEVERITY: HIGH CNTI-2026-001 ยท Apr 18 2026ICDFA Repository ยท Published May 2026

MutaCryptor Scam Network โ€” Threat Intelligence Report v2.0

First structured TI report correlating MutaEngine, VRV Security, and Zorvyn FinTech as a coordinated global internship fraud network. 8-phase attack chain ยท 18+ IOCs ยท 3 Bitcoin wallets ยท MITRE ATT&CK mapped. Infrastructure collapsed during active investigation. Officially published ICDFA Repository, May 2026.

OSINTBitcoin ForensicsMITRE ATT&CKDNS ForensicsTLP FrameworkSTIX/TAXII
๐Ÿ“„ Download Report Read Case Study โ†’
Pen Testing ยท Active Directory ยท ๐Ÿ† Week 5 Award

Active Directory Attack Simulation โ€” Pass-the-Hash

Kerberoasting, Pass-the-Hash, privilege escalation, ghost LSASS detection via Volatility. RTL ร— 0xDelta Research Week 5 Technical Precision Award winner.

MetasploitBloodHoundMimikatzVolatility
DFIR ยท Email Analysis ยท NexSecure Bootcamp

Phishing & Credential Compromise

Full DFIR investigation of a spear-phishing campaign โ€” email header forensics, payload analysis, credential exfiltration timeline, and IOC extraction.

Email ForensicsWiresharkEDRIOC Analysis
SOC ยท Malware ยท NexSecure Bootcamp

USB Malware Infection โ€” AsyncRAT

Detection and analysis of AsyncRAT delivered via USB. Sysmon event correlation, Volatility memory dump analysis, C2 communication forensics.

SysmonWiresharkVolatilityEDR
Penetration Testing ยท VAPT ยท NexSecure Bootcamp

VAPT โ€” testphp.vulnweb.com

Full vulnerability assessment and penetration test โ€” OWASP Top 10 methodology, SQL injection, XSS, IDOR discovery, and remediation recommendations.

Burp SuiteNmapSQLmapOWASP
SIEM ยท Threat Detection

SSH Brute Force Attack Detection

Splunk SIEM correlation detecting automated SSH credential stuffing โ€” log normalisation, alert tuning, IP reputation analysis, and blocklist integration.

SplunkSysmonSigma RulesAbuseIPDB
OSINT ยท Phishing Investigation ยท Mar 2026

Fake Internship Phishing โ€” Redynox & Arch Technologies

OSINT investigation of a coordinated fake internship scam network โ€” domain registration forensics, LinkedIn impersonation mapping, and threat actor profiling.

OSINTWhoisVirusTotalDomain Analysis
SIEM ยท Log Analysis

Log Correlation & Threat Detection

Splunk + Sysmon correlation rules detecting multi-stage attacks โ€” process injection, registry persistence, and lateral movement identification across the kill chain.

SplunkSysmonWindows Event LogsSigma
DFIR ยท Disk Forensics

Disk Forensics Investigation

Dead-box forensic analysis โ€” disk imaging, file system artefact recovery, deleted file reconstruction, and timeline analysis using forensic toolchain.

AutopsyFTK ImagerVolatilityTimeline Analysis
Live Projects & Builds

PRODUCTS & PLATFORMS

Available for hire

Looking to hire a SOC Analyst?

Open to remote SOC, DFIR, threat intelligence, and cybersecurity roles globally. Relocation-ready for AU, CA, US, NZ, and UAE. 5+ years, 22+ credentials, FG-LEA active.

Contact Me โฌ‡ Download CV ๐Ÿ’ฌ WhatsApp