Labs
Mini SOC Lab: Web Triage, Detection, and Containment with Wazuh
A Proxmox-based mini SOC environment with structured telemetry, custom Wazuh detection, suspicious web activity triage, and validated endpoint containment.
LLM-Assisted SOC Alert Triage with Splunk, Sysmon, Python, and OpenAI
A SOC triage lab using Splunk, Sysmon, Python, and OpenAI to structure alert analysis and compare LLM output with a manual assessment.
AWS SSRF Investigation: IMDS, CloudTrail, and Hardening
A cloud security case: I detected an SSRF attempt against an EC2-hosted application, investigated related activity in CloudTrail, and reduced the risk with IMDSv2, internal dest...
Public S3 Exposure with Access Analyzer and CloudTrail
A cloud security lab to detect, investigate, and remediate public S3 exposure using Access Analyzer, CloudTrail, EventBridge, and SNS.
PowerShell Alert Triage with Sysmon and Wazuh
Hands-on endpoint triage lab using Sysmon and Wazuh to compare PowerShell executions, inspect process-creation telemetry, and distinguish suspicious-looking activity from legiti...