Skip to content

Repository files navigation

SOC Hands On Investigations & DFIR Portfolio

A hands-on SOC / DFIR investigation portfolio showcasing real-world style lab investigations and Capture The Flag (CTF) challenges. Focused on SIEM alert triage, phishing analysis, malware analysis, endpoint detection, and network traffic analysis.

Built to demonstrate practical SOC Analyst L1/L2 and DFIR skills.

About This Repository

This repository contains hands-on SOC investigations performed in simulated and lab-based environments. It also includes CTF challenges completed on platforms like TryHackMe and Blue Team Labs Online, covering common attack scenarios faced by SOC teams.

Each investigation focuses on:

  • Identifying malicious activity
  • Analyzing indicators of compromise (IOCs)
  • Understanding attacker behavior
  • Mapping findings to MITRE ATT&CK

Covered Investigation Areas

  • Malware Analysis
  • Phishing Analysis
  • Brute Force Attacks
  • Crypto Hijacking
  • Network Traffic Analysis
  • Log Investigation (Windows & Linux)

Tools & Platforms Used

SIEM & Log Analysis

  • Splunk
  • Elastic Stack

Network & Traffic Analysis

  • Wireshark
  • Tcpdump

Malware & Sandbox Analysis

  • Any.Run
  • Joe Sandbox
  • Hybrid Analysis
  • MalwareBazaar
  • Malshare

Threat Intelligence & OSINT

  • VirusTotal
  • urlscan.io
  • AbuseIPDB
  • GreyNoise
  • IPinfo.io
  • MITRE ATT&CK

Email & Phishing Analysis

  • Message Header Analyzer
  • PhishTool
  • Email Header Analysis

Utilities

  • CyberChef
  • Linux & Windows Event Logs

Purpose of This Portfolio

  • Showcase real SOC investigation workflow
  • Demonstrate hands-on alert triage and incident analysis
  • Practice SOC Analyst L1/L2 and DFIR skills
  • Build a job-ready SOC portfolio with practical cases
  • This repository is continuously updated as I complete more labs and challenges.

Skills Demonstrated

  • SIEM Alert Triage
  • IOC Extraction & Analysis
  • Phishing Email Investigation
  • Malware Behavior Analysis
  • Log Correlation
  • Network Traffic Analysis
  • Incident Documentation
  • MITRE ATT&CK Mapping

Author

RUTHRAN-SEC | SOC Analyst | DFIR Enthusiast | Blue Team Hands-on Learning | Continuous Development

About

SOC / DFIR investigations portfolio with hands-on lab cases covering SIEM alert triage, Phishing Analysis, Malware analysis, Endpoint detection, Network Analysis. Built to demonstrate practical SOC Analyst L1/L2 and DFIR skills.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors