Evidence-led DFIR and SOC case studies developed from hands-on investigations in controlled lab environments. These are educational simulations, not production incidents.
Each report separates observed evidence from analyst assessment and documents scope, investigative reasoning, technical findings, confidence, impact, response actions, and remaining limitations.
| Case | Why it is featured | Skills demonstrated |
|---|---|---|
| Jinkies | Reconstructs a Windows workstation compromise and likely intellectual-property theft across multiple artifact sources | KAPE triage, Registry, $MFT, Windows events, Sysmon, browser history, credential analysis |
| Recollection | Uses volatile evidence to reconstruct malicious PowerShell activity, malware execution, and an attempted file transfer | Volatility, process relationships, console history, clipboard analysis, memory forensics |
| Unit42 | Follows a masqueraded download through execution, MSI staging, timestomping, and cleanup | Sysmon analysis, process chains, network telemetry, ATT&CK mapping, detection opportunities |
| PhantomRing | Profiles a Linux implant while carefully separating embedded capability from observed execution | ELF static analysis, io_uring, anti-eBPF behavior, C2 and detection engineering |
| Case | Domain | Focus |
|---|---|---|
| Brutus | DFIR · Log Analysis | Linux authentication and persistence |
| Campfire-1 | SOC · Log Analysis | Windows event logs, Prefetch, and Kerberoasting |
| Jinkies | DFIR · Incident Response | Windows endpoint compromise and data theft |
| LogJammer | SOC · Threat Detection | Windows logs, persistence, and defense evasion |
| PhantomRing | Threat Analysis · Malware | Static analysis of a Linux implant |
| Recollection | DFIR · Memory Forensics | Windows memory analysis and malicious PowerShell |
| ReliableThreat | DFIR · Threat Analysis | Windows memory, disk artifacts, and persistence |
| RogueOne | DFIR · Memory Forensics | Malicious process and C2 investigation |
| Tracer | DFIR · Log Analysis | Windows artifacts, PsExec, and lateral movement |
| Trojan | DFIR · Malware | Memory, disk, and network forensics |
| Unit42 | SOC · Threat Detection | Sysmon analysis and malicious execution |
The investigations use a consistent professional structure:
- Define the scope, available artifacts, time standard, and evidence limitations.
- Distinguish facts observed in the evidence from hypotheses and external enrichment.
- Reconstruct the incident narrative and normalized UTC timeline.
- Record indicators, affected assets, confidence, impact, and ATT&CK mappings where supported.
- Recommend containment, eradication, recovery, and detection improvements.
- Link material findings back to their supporting artifacts.
New investigations should use the full investigation template. Short-form alert decisions will be added under SOC triage using the SOC triage template.
- The current cases are based on Hack The Box Sherlocks and other controlled lab material.
- Report text, analysis, timelines, and conclusions are the portfolio work presented here.
- Source-provided artifacts, screenshots, walkthrough material, and product names remain third-party material and are identified when used.
- An external reputation result or walkthrough statement is treated as enrichment, not as independent host evidence.
- A capability, attempted action, or suspicious indicator is not described as successful impact unless the available evidence supports that conclusion.
Spoiler notice: The reports contain findings and solutions for their respective simulated scenarios, including Hack The Box Sherlocks.
