A hands-on SOC / DFIR investigation portfolio showcasing real-world style lab investigations and Capture The Flag (CTF) challenges. Focused on SIEM alert triage, phishing analysis, malware analysis, endpoint detection, and network traffic analysis.
Built to demonstrate practical SOC Analyst L1/L2 and DFIR skills.
This repository contains hands-on SOC investigations performed in simulated and lab-based environments. It also includes CTF challenges completed on platforms like TryHackMe and Blue Team Labs Online, covering common attack scenarios faced by SOC teams.
Each investigation focuses on:
- Identifying malicious activity
- Analyzing indicators of compromise (IOCs)
- Understanding attacker behavior
- Mapping findings to MITRE ATT&CK
- Malware Analysis
- Phishing Analysis
- Brute Force Attacks
- Crypto Hijacking
- Network Traffic Analysis
- Log Investigation (Windows & Linux)
- Splunk
- Elastic Stack
- Wireshark
- Tcpdump
- Any.Run
- Joe Sandbox
- Hybrid Analysis
- MalwareBazaar
- Malshare
- VirusTotal
- urlscan.io
- AbuseIPDB
- GreyNoise
- IPinfo.io
- MITRE ATT&CK
- Message Header Analyzer
- PhishTool
- Email Header Analysis
- CyberChef
- Linux & Windows Event Logs
- Showcase real SOC investigation workflow
- Demonstrate hands-on alert triage and incident analysis
- Practice SOC Analyst L1/L2 and DFIR skills
- Build a job-ready SOC portfolio with practical cases
- This repository is continuously updated as I complete more labs and challenges.
- SIEM Alert Triage
- IOC Extraction & Analysis
- Phishing Email Investigation
- Malware Behavior Analysis
- Log Correlation
- Network Traffic Analysis
- Incident Documentation
- MITRE ATT&CK Mapping
RUTHRAN-SEC | SOC Analyst | DFIR Enthusiast | Blue Team Hands-on Learning | Continuous Development