A hands-on Blue Team portfolio documenting real cybersecurity investigations using Wireshark, Linux, Nmap, and enterprise networking labs.
This repository showcases practical SOC Analyst skills built through hands-on investigations rather than theory. Every project contains packet captures, Linux commands, evidence, screenshots, methodology, and findings.
| # | Investigation | Status |
|---|---|---|
| 01 | SSH Brute Force Investigation | β |
| 02 | ARP Spoofing (MITM) Investigation | β |
| 03 | DNS Traffic Analysis | β |
| 04 | DNS Tunnelling Detection | β |
| 05 | HTTP vs HTTPS Investigation | β |
| 06 | TLS Handshake Analysis | β |
| 07 | DHCP Investigation (DORA Process) | β |
| 08 | Nmap Reconnaissance Detection | β |
- Packet Analysis
- TCP/IP
- DNS
- DHCP
- ARP
- HTTP / HTTPS
- TLS
- Network Reconnaissance Detection
- Credential Exposure Analysis
- MITM Traffic Analysis
- DNS Tunnelling Detection
- Wireshark Investigation Methodology
- Wireshark
- Nmap
- tcpdump
- Apache2
- OpenSSL
- Linux Terminal
| Machine | Purpose |
|---|---|
| Kali Linux | Attacker / SOC Analyst |
| Ubuntu | Victim Workstation |
| Wireshark | Packet Capture & Analysis |
| VirtualBox | Isolated Lab Environment |
- Networking & Packet Analysis
- 8 SOC Investigations
- Linux for SOC
- Splunk SIEM
- CompTIA Security+
- TryHackMe SOC Level 1
This journal represents my transition from Enterprise IT into Blue Team Cybersecurity by documenting real investigations, analytical thinking, and practical defensive skills.
Every packet tells a story. Every investigation builds a better defender.