Investigating Suspicious Encoded PowerShell Execution
Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.
Cybersecurity analyst focused on threat detection, incident investigation, SIEM log analysis, and web application security.
I document my SOC investigations, security labs, projects, and research while building practical security tools for developers and small businesses.
Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.
Investigation of over 12,000 failed SSH authentication attempts on an internet-facing Linux bastion host, identifying dictionary brute-force patterns and misconfigured firewall rules.
Dissection of an obfuscated SVG/HTML attachment designed to steal Microsoft 365 credentials through credential harvesting and iframe cloaking.
Analysis of network flow logs and Suricata NIDS alerts detecting horizontal TCP SYN sweep activity from an unauthorized development workstation.
Log analysis and triage of blind Boolean-based SQL injection attempts against a vulnerable plugin endpoint on a WordPress web server.
A dedicated virtualized SOC engineering environment with Windows 11 endpoints, Sysmon, Splunk Enterprise, and Atomic Red Team for detection rule testing.
A passive security auditing utility that analyzes HTTP response headers, TLS posture, DNS security records, and exposed technology banners.
A browser-native threat intelligence utility that parses, deduplicates, and defangs Indicators of Compromise from unformatted text and logs.
A structured audit framework and configuration template designed to harden production WordPress sites against common exploitation paths.
Passive assessment of website security posture including HTTP security headers, TLS observations, and DNS security records.
Evaluates individual HTTP response headers against current defensive best practices and provides remediation guidance.
Inspects URLs for heuristic risk factors such as suspicious TLDs, IP hosts, excessive subdomains, and obfuscated query strings without visiting the target.
Extracts, deduplicates, and defangs Indicators of Compromise (IPs, domains, hashes, URLs, CVEs) from raw logs and text.
Parses raw RFC 822 email headers to trace Received hop latency, verify SPF/DKIM/DMARC authentication, and flag spoofed return paths.
Search utility for National Vulnerability Database (NVD) entries, CVSS scores, and known exploited vulnerabilities (KEV).
A walkthrough of the exact triage workflow, event correlation steps, and command-line decoding techniques used to analyze suspicious PowerShell execution.
A concise reference guide to the most valuable Windows Event Log IDs for detecting account tampering, lateral movement, and privilege escalation.
Why modern web applications need CSP, HSTS, and X-Content-Type-Options, and how to configure them properly in Next.js and Nginx.
Practical techniques for parsing /var/log/auth.log, aggregating attacking subnets, and verifying whether key-only policies prevented breach.
Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.
A passive security auditing utility that analyzes HTTP response headers, TLS posture, DNS security records, and exposed technology banners.
Investigation of over 12,000 failed SSH authentication attempts on an internet-facing Linux bastion host, identifying dictionary brute-force patterns and misconfigured firewall rules.
Alert triage, log analysis, SIEM correlation, threat detection, incident investigation, and containment procedures across Windows and Linux environments.
Web application vulnerabilities, OWASP Top 10, authentication, authorization flaws, API security, defensive HTTP headers, and WordPress hardening.
Practical security utilities, automated detection testing, IOC parsing, threat intelligence utilities, and reproducible lab environments.
Passive assessment of website security posture including HTTP security headers, TLS observations, and DNS security records.
Evaluates individual HTTP response headers against current defensive best practices and provides remediation guidance.
Inspects URLs for heuristic risk factors such as suspicious TLDs, IP hosts, excessive subdomains, and obfuscated query strings without visiting the target.
Extracts, deduplicates, and defangs Indicators of Compromise (IPs, domains, hashes, URLs, CVEs) from raw logs and text.
Parses raw RFC 822 email headers to trace Received hop latency, verify SPF/DKIM/DMARC authentication, and flag spoofed return paths.
Search utility for National Vulnerability Database (NVD) entries, CVSS scores, and known exploited vulnerabilities (KEV).
A walkthrough of the exact triage workflow, event correlation steps, and command-line decoding techniques used to analyze suspicious PowerShell execution.
A concise reference guide to the most valuable Windows Event Log IDs for detecting account tampering, lateral movement, and privilege escalation.
Why modern web applications need CSP, HSTS, and X-Content-Type-Options, and how to configure them properly in Next.js and Nginx.
Practical hardware and software recommendations for home labs, web security, and SOC learning.
A thorough hands-on review of the AMD Ryzen 7 5800H Mini PC running Proxmox VE 8, Windows Server 2022 domain controllers, and Splunk Enterprise.
A defensive security breakdown of Yubico’s flagship hardware security keys for FIDO2/WebAuthn, U2F, and hardware-backed SSH authentication.
An in-depth review of Bitwarden’s zero-knowledge architecture, client-side encryption, self-hosting Vaultwarden options, and YubiKey integration.
My path into defensive cybersecurity is grounded in practical web engineering. Prior to focusing on SOC operations and threat detection, I spent several years developing and maintaining web applications, WordPress installations, and client digital infrastructure.
Working across DNS configurations, Cloudflare edge settings, server access logs, and application layers provided a natural foundation for understanding how attackers exploit web vulnerabilities, manipulate HTTP protocols, and abuse trust boundaries. Today, that builder’s perspective directly informs how I triage alerts, dissect logs, and evaluate attack surfaces.