Deep Blue Investigation
Windows event log investigation involving suspicious process execution, Meterpreter style activity, service creation, and local account persistence.
View projectWelcome to my cybersecurity project portfolio. This site highlights hands on technical work across SOC analysis, digital forensics, incident response, malware analysis, threat intelligence, and detection engineering.
My goal is to show practical cybersecurity skills beyond certifications by documenting how I investigate alerts, reconstruct attacks, analyze evidence, map activity to MITRE ATT&CK, and communicate findings clearly.
This portfolio is designed to give recruiters, hiring managers, and security professionals a clear view of my practical cybersecurity work. Each project focuses on how I approach evidence, analyze attacker behavior, document findings, and connect technical activity to defensive security outcomes.
The main purpose of this site is to show how I think as a blue team analyst. Instead of only listing certifications, this portfolio shows investigations, case notes, detection logic, forensic analysis, threat intelligence research, and technical walkthroughs that demonstrate applied skill.
These projects document hands on defensive security work across lab environments, public training platforms, personal research, and sanitized professional experience.
Windows event log investigation involving suspicious process execution, Meterpreter style activity, service creation, and local account persistence.
View projectHands on defensive security certification project focused on enterprise intrusion analysis, incident response, evidence correlation, and professional reporting.
View projectBlue team certification lab covering phishing analysis, SIEM investigations, digital forensics, incident response, threat intelligence, and defensive reporting.
View projectSOC analyst certification lab covering alert triage, cloud log review, AWS log analysis, threat detection, incident workflow, and investigation reporting.
View projectSecurity analyst certification project focused on SOC workflows, alert investigation, defensive operations, security tooling, and practical analyst decision making.
View projectHands on security lab bundle covering reconnaissance, enumeration, web application testing, cloud security, cryptography, malware concepts, and security tooling.
View projectBusiness Email Compromise investigation using Azure audit logs, email exports, suspicious inbox rules, and financial fraud indicators.
View projectHands on lab bundle covering reconnaissance, enumeration, web application testing, cloud security, cryptography, and security tooling.
View projectSandbox and threat intelligence analysis of Stealc malware behavior, credential theft, configuration details, and MITRE ATT&CK mapping.
View projectIncident response simulation focused on unauthorized email access, lateral movement, containment, recovery, and response decision making.
View projectIncident response simulation involving unauthorized access, data exfiltration concerns, containment, escalation, and recovery planning.
View projectData theft tabletop exercise involving administrator misuse, cloud activity, Linux and Mac systems, containment, and team communication.
View projectThreat intelligence investigation involving InfoStealer activity, malicious infrastructure, IOC extraction, and cryptocurrency wallet movement.
View projectDefensive exercise design focused on attacker actions, defender counters, evidence sources, telemetry, and detection gap identification.
View projectSanitized detection engineering project mapping attacker behavior, telemetry, and detection logic across multiple security tools.
View projectMalicious browser extension analysis covering obfuscation, credential theft, keylogging, cookie access, AES encryption, and exfiltration.
View projectEndpoint memory forensics focused on suspicious PowerShell activity, remote DLL execution, user context, and malware identification.
View projectPacket capture investigation of Apache ActiveMQ exploitation, OpenWire traffic, malicious XML retrieval, and reverse shell payload delivery.
View projectSOC investigation lab focused on Microsoft Sentinel incidents, Log Analytics, entity review, incident ownership, and escalation workflow.
View projectForensic investigation involving suspicious RDP activity, browser history, Slack usage, Google Drive activity, and Windows Defender logs.
View projectMemory based malware investigation using Volatility 2, malfind, SSDT hooks, driver dumping, and SHA256 enrichment.
View projectForensic disk image investigation involving Autopsy, Windows artifacts, messaging data, browser history, thumbnail cache, and SQLite review.
View projectThreat intelligence investigation involving Base64 decoding, ExifTool metadata, IOC extraction, adversary analysis, and web shell attribution.
View projectSplunk based SOC simulator lab focused on phishing alerts, suspicious emails, attachment evidence, case reports, and True Positive closure.
View projectLive phishing attack simulation involving PowerShell execution, reverse shell behavior, suspicious DNS requests, and case reporting.
View projectSafe analysis of real phishing messages using ANY.RUN to inspect suspicious links, redirect behavior, attacker intent, and indicators.
View projectThis portfolio is being actively expanded with more blue team investigations, lab writeups, and sanitized detection engineering work. The goal is to show both technical depth and clear communication across defensive cybersecurity domains.