WiLLson โžŸ ๐Ÿ‘จโ€๐Ÿ’ป ๐Ÿ

@themeek766.bsky.social

๐Ÿ‘จ๐Ÿฝโ€๐Ÿ’ป| I write about Tech, SOC workflows, SIEM alerts, threat analysis, and incident response so you can think like a blue-team analyst.

๐Ÿ›ก๏ธ 28-day SOC build. In public. No filler. Every project here is a detection I wrote or an incident I walked end-to-end not a tutorial replay. ๐Ÿ” Splunk ยท SIEM ยท Log Analysis ๐Ÿง  MITRE ATT&CK ยท Threat Detection ๐Ÿ’ป Kali ยท Ubuntu ยท Windows home lab ๐Ÿ“œ ISC2 CC This is what hire-ready looks like ๐Ÿ‘‡

Bild

30-Day Cybersecurity Learning Journey OverTheWire Bandit CTF Documentation (Day 1โ€“10) ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐—ฑ ๐Ÿงต 1/ ๐—ข๐˜ƒ๐—ฒ๐—ฟ๐—ง๐—ต๐—ฒ๐—ช๐—ถ๐—ฟ๐—ฒ ๐—•๐—ฎ๐—ป๐—ฑ๐—ถ๐˜ โ€“ ๐—Ÿ๐—ฒ๐˜ƒ๐—ฒ๐—น 0 โ†’ 1 (๐——๐—ฎ๐˜† 1) I started my cybersecurity learning journey by exploring the Bandit wargame.

BildBild

๐——๐—ฎ๐—ถ๐—น๐˜† ๐—–๐—ง๐—™ ๐——๐—ถ๐˜€๐—ฐ๐—ถ๐—ฝ๐—น๐—ถ๐—ป๐—ฒ ~ ๐—ข๐˜ƒ๐—ฒ๐—ฟ๐—ง๐—ต๐—ฒ๐—ช๐—ถ๐—ฟ๐—ฒ ๐—๐—ผ๐˜‚๐—ฟ๐—ป๐—ฒ๐˜† Real technical skill isnโ€™t built in bursts. Itโ€™s built through consistency. Iโ€™ve committed to 30 minutes every day to complete one OverTheWire level until I finish the entire series. The goal isnโ€™t just solving challenges.

BildBild

๐—ง๐—ต๐—ฒ ๐—ฆ๐—จ๐—ฆ๐—ฃ๐—œ๐—–๐—œ๐—ข๐—จ๐—ฆ ๐—ก๐—ฒ๐˜๐˜„๐—ผ๐—ฟ๐—ธ ๐—™๐—น๐—ผ๐˜„ โ€“ ๐——๐—ฒ๐—ฐ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ ๐Ÿต, ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ SOC network logs showed one device sending unusual traffic to a rarely used external IP. Investigation revealed malware beaconing for C2 communication. Immediate containment stopped lateral movement and prevented data theft.

๐Ÿšจ๐—ฅ๐—ฎ๐—ป๐˜€๐—ผ๐—บ๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—•๐—ฒ๐—ต๐—ฎ๐˜ƒ๐—ถ๐—ผ๐—ฟ ๐—Ÿ๐—ฎ๐—ฏ (๐—•๐—ฒ๐—ด๐—ถ๐—ป๐—ป๐—ฒ๐—ฟ ๐—ฆ๐—ข๐—–) Ransomware isnโ€™t just malware. Itโ€™s patterns. In a controlled lab I simulated: โ€ข Mass file changes โ€ข AES encryption โ€ข Files renamed to .locked โ€ข A ransom note dropped

BildBildBild

๐Ÿšจ Beginner SOC Lab: Catching Sneaky Access I built a small home lab to practice as a SOC analyst. Setup: โ€ข Windows 11 VM (victim) โ€ข Kali Linux VM (attacker) โ€ข Shared โ€œHRโ€ folder with a Canarytoken inside Simulated an attack: โ€ข Found the SMB share โ€ข Opened files โ€ข Triggered the Canarytoken๏ฟผ

BildBildBildBild

๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง๐Ÿง๐Ÿง๐Ÿง ๐Ÿง๐Ÿง๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง๐Ÿง๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง ๐Ÿง

๐—Ÿ๐—ฎ๐˜๐—ฒ๐—ฟ๐—ฎ๐—น ๐— ๐—ผ๐˜ƒ๐—ฒ๐—บ๐—ฒ๐—ป๐˜ & ๐—ฃ๐—ฒ๐—ฟ๐˜€๐—ถ๐˜€๐˜๐—ฒ๐—ป๐—ฐ๐—ฒ Lateral movement = breaking into one system, then sneaking into others using stolen creds or tools. Persistence = staying hidden with auto-start programs or fake accounts. SOC teams hunt this using logs + smart detection rules ๐Ÿ›ก๏ธ