![]() Wireshark |
![]() Splunk |
![]() Sysmon |
![]() Volatility 3 |
![]() RegRipper |
![]() bulk_extractor |
FTK Imager |
Velociraptor |
Timesketch |
![]() EZ Tools |
Hands-on documentation of my security training: DFIR/SOC labs, CTF writeups, and certification coursework. Everything here is practice-work β rebuildable, reviewed, and written from a blue-team perspective (each investigation ends with detection & mitigation takeaways).
The main project: a complete, hands-on DFIR investigation through Blue Cape Security's DFIR Foundations and Techniques course β the compromise of a single workstation (Client2.BCS.local, "Alice") followed end-to-end across network, SIEM/EDR, memory, disk, and timeline evidence.
- Every lab is self-contained (
README.md) β commands explained at the flag level, evidence embedded inline. - Full attack-chain reconstruction:
Scenario-Reveal.md. - Certificate:
DFIR-Certificate.pdfβ 94.37% (67/71), 8 CEUs.
| Folder | Content | Status |
|---|---|---|
Blue-Cape-DFIR/ |
Full DFIR investigation course (see Spotlight) | β Documented |
TryHackMe/ |
Labs: Hacker Holidays, Investigate-Windows | β Documented |
HackTheBox/ |
Sherlocks: Brutus, PhantomRing, Unit42 + web cheat sheet | β Documented |
SANS-ctf/ |
AWS Skills to Jobs CTF 2026 β 6 writeups + timing attack | β Documented |
CyberDefenders/ |
FakeGPT-Lab walkthrough | β Documented |
Google-Cybersecurity/ |
Google Cybersecurity Certificate β courses 1β9 notes | π§ In progress (course notes) |
LetsDefend/ |
Malware Analysis & Cybersecurity Fundamentals | π§ Starter only |
TheForage/ |
TATA Cybersecurity Analyst job simulation | π§ Starter only |
BTLO/ |
Blue Team Labs Online | β³ To come |
BOTS/ |
BOTS (SOC simulation) | β³ To come |
- Done β Blue-Cape-DFIR full investigation, SANS CTF writeups, 3 HackTheBox Sherlocks, TryHackMe labs, FakeGPT-Lab.
- In progress β Google Cybersecurity Certificate notes, LetsDefend fundamentals, TheForage simulation.
- To come β BTLO and BOTS SOC-style labs.
Prefer starting from the inside: each subfolder has its own self-contained README.md covering the how and why behind every finding.


.png)








