👨💻New milestone in my SOC L2 journey. Completed TryHackMe's Active Directory for SOC module. And for those leveling up in SOC L2+ territory: a new Windows Incident Response & Forensics path is coming in November. Looking forward to diving in. #SOCAnalyst #BlueTeam
Citadel Cybersec
@citadelcysec.bsky.social
Cybersecurity Analyst | Security+ | CCDL1 | BTL1 | SAL1 | AZ-900 | Splunk Cert | Google Cert | TryHackMe Top 1% | 💼 Available for Hire | https://linktr.ee/citadelcybersec
From Splunk to Sigma 🔍 I rebuilt a suspicious PowerShell detection as a Sigma rule, then converted it back to SPL and tested it with existing telemetry + Atomic Red Team. medium.com/@citadelcybe... #Cybersecurity #DetectionEngineering #Homelab
From Splunk to Sigma: Building and Validating Vendor-Neutral Detection Logic
A detection-engineering exercise using Sigma, Splunk, Windows telemetry, and Atomic Red Team to validate vendor-neutral detection logic.
medium.com
365 days on TryHackMe! 🔥 🏆 Top 1% 🧪 280 rooms done 🔎 50+ investigations published 🎓 SAL1 Cert 📊 SOC L1 Completed & L2 (30%) 🤖 AI Security Completed After 13+ yrs in design, I’m transitioning into cyber & looking for an entry-level role 365 days down. Ready for the next challenge 🚀 #Cybersecurity
A detection can look perfect in Splunk and still fail against real endpoint telemetry. I tested my PowerShell detections with Atomic Red Team and MITRE ATT&CK T1027. One passed. One failed. I investigated why, refined the detection & improved the alert for SOC triage. #Cybersecurity #SOCAnalyst
From Manual Testing to Repeatable Detection Validation with Atomic Red Team
How to Validate PowerShell Detections in Splunk with Sysmon, Atomic Red Team, and MITRE ATT&CK
medium.com
The new TryHackMe SOC Level 2 path is an interesting look at how the SOC analyst role is evolving: AD, Entra ID, AWS, threat hunting, Sigma, CTI, net analysis, detection engineering, AI/automation... I wrote a deeper analysis here: medium.com/@citadelcybe... #Cybersecurity #SOC #tryhackme
TryHackMe SOC Level 2: What Changed, and What It Says About the Future of the SOC Analyst Role
Exploring the new skills, technologies and investigative mindset behind TryHackMe’s updated L2 curriculum
medium.com
Once you understand how the AI system works, you can begin evaluating specific attack techniques, like Prompt injection. Lakera Gandalf provided a fun, hands-on way to explore how these attacks can influence LLM behavior. No longer online, but more challenges are here: play.lakera.ai/agent-breaker
How do you assess the security of an AI system? In my latest article I share what I learned from INE's AI Systems Security Specialist learning path, mainly, how to think systematically about AI-enabled systems: architecture, trust boundaries, data flows, APIs... #CyberSecurity #AISecurity
Beyond AI Security: Learning How to Assess AI Systems
My Experience with INE’s AI Systems Security Specialist (eAIS) Learning Path
medium.com
In my new article "AI Security: Cybersecurity Applied to a New Attack Surface", I share my experience completing TryHackMe's AI Security learning path, covering prompt injection, RAG security, AI forensics, supply chain risks, and key AI security insights. #Cybersecurity #AISecurity #InfoSec
AI Security: Cybersecurity Applied to a New Attack Surface
A reflection on completing TryHackMe’s AI Security learning path
medium.com
What should a SOC analyst see within the first minute of a shift? I built a Tier 1 SOC Dashboard in Splunk to answer that question using my SOC homelab with Active Directory, Sysmon, pfSense, and Windows telemetry; design decisions, SPL, and detections behind it. #CyberSecurity #Splunk #SOCAnalyst
Building a Tier 1 SOC Dashboard in Splunk
Designing an operational dashboard for authentication, endpoint, network, and threat hunting visibility
medium.com
New article: SOC Homelab #5 Investigated AD authentication & lateral movement in Splunk, including logons, Kerberos, SMB admin shares, Sysmon, and attempted WinRM/WMI/Scheduled Tasks execution.👇 medium.com/@citadelcybe... #CyberSecurity #SOC #Splunk
Investigating Lateral Movement and Authentication Activity in Active Directory Using Splunk
Correlating failed logons, Kerberos authentication events, SMB access, and blocked lateral movement attempts in a hardened Active Directory…
medium.com
A hands-on SOC analyst exercise focused on investigation and triage. I simulated suspicious PowerShell activity on a Windows 11 endpoint and investigated it using Sysmon, PowerShell logging, and Splunk. #CyberSecurity #BlueTeam New homelab write-up:
Investigating Suspicious PowerShell Activity with Splunk
Simulating attacker techniques, analyzing endpoint telemetry, and building a detection rule in a SOC homelab.
medium.com
Built a SOC homelab with pfSense, Active Directory, Windows, Sysmon, and Splunk. The most valuable part wasn't the setup, it was solving problems: • Missing telemetry • DNS failures • Time sync issues • Segmentation mistakes #CyberSecurity #SOCAnalyst #BlueTeam
6 Real Problems I Solved While Building My SOC Homelab
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
medium.com
I investigated a Volt Typhoon-inspired intrusion using a real-world SOC methodology rather than a typical lab approach. The result was a full incident report covering timeline reconstruction, threat hunting & MITRE ATT&CK mapping through different phases. #CyberSecurity #SOCAnalyst #ThreatHunting
SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion
A Complete Write-Up Demonstrating Real SOC Investigation Methodology
medium.com
Built a SOC homelab from scratch featuring Active Directory, pfSense, Sysmon, Windows Event Logging, and Splunk Enterprise. In this new article I get into Networking, Segmentation, Firewall, Logs and Telemetry details. #Cybersecurity #Splunk #homelab
Building a SOC Homelab from Scratch: Active Directory, pfSense, Sysmon, and Splunk
Designing an Enterprise-Style Security Monitoring Environment for Blue Team Skill Development
medium.com
“The impediment to action advances action. What stands in the way becomes the way.” Marcus Aurelius, Meditations.
100+ cybersecurity labs taught me incident response. Building my own SOC homelab taught me how enterprise systems actually work. pfSense | AD | Win11 | Splunk | Sysmon | Centralized logs New blog series is live (link below). #CyberSecurity #SOCAnalyst #BlueTeam
I Completed 100 Cybersecurity Labs. Why Build a SOC Homelab Too?
Lessons learned building a SOC homelab with Splunk, Active Directory, Sysmon, and pfSense
medium.com
“The wise mind adapts to circumstance without surrendering virtue.” Confucius
I knew what I needed to know to become a SOC analyst. But how do you learn to think like one? I wrote a review of CyberDefenders CCDL1. A certification focused on real SOC investigations: SIEM (Splunk & Sentinel), DFIR, phishing analysis & cloud security workflows. #cybersecurity #BlueTeam #DFIR
CyberDefenders CCDL1 Review — Practical SOC Analyst Training Beyond the Fundamentals
A hands-on path into modern blue team operations
medium.com
I published a Conti ransomware investigation treating it as a live SOC incident instead of a CTF. I reconstructed the full attack chain using Splunk, Sysmon, and Windows logs, covering web shell access, credential dumping, privilege escalation, persistence, and execution. medium.com/@citadelcybe...
SOC Alert Reporting: Conti Ransomware Investigation Using Splunk
Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation
medium.com
Thrilled to be a #CertifiedCyberDefender! CyberDefenders CCDL1 built on my SOC foundation with hands-on Splunk threat hunting, Windows/Linux forensics & AWS cloud investigations. Strengthened investigative workflows & MITRE ATT&CK use for real-world SOC challenges. #BlueTeam #DFIR #CyberSecurity
Published a new DFIR write-up on investigating a phishing attack using Volatility 3 and Olevba. The walkthrough covers malicious macros, memory forensics, C2 analysis, process investigation, and persistence detection from the TryHackMe Boogeyman 2 room. #CyberSecurity #DFIR #SOCAnalyst
Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2
A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.
medium.com
A “Potential Ransom Note” alert turned into a full ransomware investigation across endpoint, network, and AWS logs. In this write-up, I break down how I reconstructed the attack using Splunk — from persistence and lateral movement to S3 data exfiltration. #CyberSecurity #ThreatHunting #Ransomware
Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night
Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration
medium.com
Reverse Shell Alert: SOC Investigation Writeup I analyzed PCAPs + Splunk logs to uncover: • C2 channel • ARP spoofing (MITM) • DNS data exfiltration • Plaintext credential leak If you're into #CyberSecurity, #SOCAnalysis, or #TryHackMe this is for you. #NetworkSecurity #DFIR #BlueTeam
Unraveling a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel
Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques
medium.com
🔍Just published a detailed SOC investigation based on a TryHackMe CTF, analyzing a multi-stage attack using Splunk. From malicious file execution to credential dumping with Mimikatz and lateral movement. #CyberSecurity #SOCAnalyst #Splunk #ThreatHunting #IncidentResponse
Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance
Hands-on Splunk analysis covering initial access, persistence, credential dumping, and lateral movement
medium.com
🕵️♂️I analyzed a full attack chain: Brute force → Web shell → Data exfiltration Working with: · Web server and WAF logs · XDR telemetry · MITRE ATT&CK mapping TryHackMe First Shift CTF – Task 5: Portal Drop Writeup #cybersecurity #socanalyst #blueteam #tryhackme #incidentresponse
Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop
A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence
medium.com
New write-up: Inside a Phishing Attack — TryHackMe First Shift CTF, Task 4. I walk through a real SOC-style phishing investigation: email header analysis, DMARC findings, attachment decoding, obfuscation, MITRE ATT&CK mapping, and threat actor attribution. #Cybersecurity #Phishing
Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books
A SOC phishing analysis: email header forensics, obfuscated payload decoding, and adversary attribution
medium.com
Growing steadily in Defensive Security 🔒 My TryHackMe Capability Score places me at a Mid-level Security Professional, showing the power of persistence and curiosity. Focused on: SOC challenges, real-world scenarios, and continuous learning documented in write-ups. Learning. Adapting. Defending.
🧑💻 I just published a hands-on SOC investigation from TryHackMe’s First Shift CTF (Task 3), covering: • Threat intelligence analysis • IOC enrichment • Malware investigation • MITRE ATT&CK mapping #CyberSecurity #ThreatIntelligence #BlueTeam #InfoSec
A SOC Threat Intelligence Investigation. TryHackMe First Shift CTF — Task 3: Probably Just Fine
A practical walkthrough of SOC investigation techniques, including IOC analysis, malware classification, and MITRE ATT&CK mapping.
medium.com
“We are what we repeatedly do. Excellence, then, is not an act, but a habit.” Aristotle