Citadel Cybersec

@citadelcysec.bsky.social

Cybersecurity Analyst | Security+ | CCDL1 | BTL1 | SAL1 | AZ-900 | Splunk Cert | Google Cert | TryHackMe Top 1% | 💼 Available for Hire | https://linktr.ee/citadelcybersec

A detection can look perfect in Splunk and still fail against real endpoint telemetry. I tested my PowerShell detections with Atomic Red Team and MITRE ATT&CK T1027. One passed. One failed. I investigated why, refined the detection & improved the alert for SOC triage. #Cybersecurity #SOCAnalyst

From Manual Testing to Repeatable Detection Validation with Atomic Red Team

How to Validate PowerShell Detections in Splunk with Sysmon, Atomic Red Team, and MITRE ATT&CK

medium.com

The new TryHackMe SOC Level 2 path is an interesting look at how the SOC analyst role is evolving: AD, Entra ID, AWS, threat hunting, Sigma, CTI, net analysis, detection engineering, AI/automation... I wrote a deeper analysis here: medium.com/@citadelcybe... #Cybersecurity #SOC #tryhackme

TryHackMe SOC Level 2: What Changed, and What It Says About the Future of the SOC Analyst Role

Exploring the new skills, technologies and investigative mindset behind TryHackMe’s updated L2 curriculum

medium.com

What should a SOC analyst see within the first minute of a shift? I built a Tier 1 SOC Dashboard in Splunk to answer that question using my SOC homelab with Active Directory, Sysmon, pfSense, and Windows telemetry; design decisions, SPL, and detections behind it. #CyberSecurity #Splunk #SOCAnalyst

Building a Tier 1 SOC Dashboard in Splunk

Designing an operational dashboard for authentication, endpoint, network, and threat hunting visibility

medium.com

I investigated a Volt Typhoon-inspired intrusion using a real-world SOC methodology rather than a typical lab approach. The result was a full incident report covering timeline reconstruction, threat hunting & MITRE ATT&CK mapping through different phases. #CyberSecurity #SOCAnalyst #ThreatHunting

SOC Incident Report: Investigation of a Volt Typhoon-Inspired Intrusion

A Complete Write-Up Demonstrating Real SOC Investigation Methodology

medium.com

I published a Conti ransomware investigation treating it as a live SOC incident instead of a CTF. I reconstructed the full attack chain using Splunk, Sysmon, and Windows logs, covering web shell access, credential dumping, privilege escalation, persistence, and execution. medium.com/@citadelcybe...

SOC Alert Reporting: Conti Ransomware Investigation Using Splunk

Simulating Real-World SOC Triage, Threat Hunting, and Incident Reporting Through a Conti Ransomware Investigation

medium.com

Published a new DFIR write-up on investigating a phishing attack using Volatility 3 and Olevba. The walkthrough covers malicious macros, memory forensics, C2 analysis, process investigation, and persistence detection from the TryHackMe Boogeyman 2 room. #CyberSecurity #DFIR #SOCAnalyst

Investigating a Phishing Attack with Volatility and Olevba | TryHackMe Boogeyman 2

A hands-on DFIR walkthrough covering phishing analysis, malicious macros, memory forensics, C2 investigation, and persistence detection.

medium.com

A “Potential Ransom Note” alert turned into a full ransomware investigation across endpoint, network, and AWS logs. In this write-up, I break down how I reconstructed the attack using Splunk — from persistence and lateral movement to S3 data exfiltration. #CyberSecurity #ThreatHunting #Ransomware

Unraveling a Ransomware Attack Chain: TryHackMe First Shift CTF — Task 8: Promotion Night

Hands-on Splunk investigation covering ransomware deployment, persistence mechanisms, lateral movement, and AWS data exfiltration

medium.com

Reverse Shell Alert: SOC Investigation Writeup I analyzed PCAPs + Splunk logs to uncover: • C2 channel • ARP spoofing (MITM) • DNS data exfiltration • Plaintext credential leak If you're into #CyberSecurity, #SOCAnalysis, or #TryHackMe this is for you. #NetworkSecurity #DFIR #BlueTeam

Unraveling a Network-Based Attack: TryHackMe First Shift CTF — Task 7: The Crown Jewel

Network Traffic Analysis and Forensics to Identify C2 Channels, ARP Spoofing, and Data Exfiltration Techniques

medium.com

🔍Just published a detailed SOC investigation based on a TryHackMe CTF, analyzing a multi-stage attack using Splunk. From malicious file execution to credential dumping with Mimikatz and lateral movement. #CyberSecurity #SOCAnalyst #Splunk #ThreatHunting #IncidentResponse

Investigating a Multi-Stage Attack: TryHackMe First Shift CTF — Task 6: Zero Tolerance

Hands-on Splunk analysis covering initial access, persistence, credential dumping, and lateral movement

medium.com

🕵️‍♂️I analyzed a full attack chain: Brute force → Web shell → Data exfiltration Working with: · Web server and WAF logs · XDR telemetry · MITRE ATT&CK mapping TryHackMe First Shift CTF – Task 5: Portal Drop Writeup #cybersecurity #socanalyst #blueteam #tryhackme #incidentresponse

Inside a Web Shell Attack: TryHackMe First Shift CTF — Task 5: Portal Drop

A SOC Threat Intelligence Investigation into Brute Force, File Upload Exploitation, and Web Shell Persistence

medium.com

New write-up: Inside a Phishing Attack — TryHackMe First Shift CTF, Task 4. I walk through a real SOC-style phishing investigation: email header analysis, DMARC findings, attachment decoding, obfuscation, MITRE ATT&CK mapping, and threat actor attribution. #Cybersecurity #Phishing

Inside a Phishing Attack: TryHackMe First Shift CTF — Task 4: Phishing Books

A SOC phishing analysis: email header forensics, obfuscated payload decoding, and adversary attribution

medium.com

Growing steadily in Defensive Security 🔒 My TryHackMe Capability Score places me at a Mid-level Security Professional, showing the power of persistence and curiosity. Focused on: SOC challenges, real-world scenarios, and continuous learning documented in write-ups. Learning. Adapting. Defending.

Bild

My new post on my TryHackMe Splunk 2 (Bots v2) investigation covers: • Data collection & filtering • Deep-dive into raw event logs • Pattern recognition & correlation • Identifying phishing & exfiltration activity A practical look at real SOC investigation workflows. #InfoSec #BlueTeam #Splunk

Splunk 2 TryHackMe Writeup (Part 1) — BOTS v2 SOC Investigation (100 & 200 Series)

Practical Log Analysis from the Boss of the SOC (BOTS v2) Dataset

medium.com