Hello! I'm an aspiring IT professional and SOC analyst based in Auckland, NZ, working toward a career in cybersecurity and system administration.
This repository documents my hands-on learning through TryHackMe labs, homelabs, and practical IT fundamentals.
Security Tools & Concepts:
- Network analysis (Wireshark, packet inspection, protocol analysis)
- Windows event log analysis and correlation
- Sysmon for process monitoring and threat detection
- PowerShell for system administration and forensics
- MITRE ATT&CK framework for threat classification
- Incident response workflows and log investigation
- SIEM fundamentals (log aggregation, alerting)
- DNS tunneling and ARP MITM attack detection
- Log4j vulnerability exploitation and detection
IT Fundamentals:
- Windows Server administration and configuration
- System monitoring and performance troubleshooting
- Command-line tools (PowerShell, Bash, Linux fundamentals)
- Network troubleshooting and enumeration (FTP, Nmap, Telnet, POP3)
- Security best practices and hardening
- Phishing Sysmon Analysis - malware detection through process monitoring
- USB Malware Analysis - USB propagation and execution detection
- User Backdoor Detection - detecting unauthorized user creation and privilege escalation
- Process Analysis with Sysmon - analyzing browser processes, downloaded files, and network connections
- Detecting Discovery Commands - identifying reconnaissance and defense evasion techniques
- Detecting Data Stealer Collection - clipboard theft and data exfiltration detection
- Backdoor User Detection - unauthorized account creation and access patterns
- C2 Detection - command and control communications identification
- Service & Task Persistence - malicious service and scheduled task detection
- Startup Folder & Run Key Persistence - registry persistence mechanism detection
- Advanced Filters - TCP checksum validation, TTL analysis, version detection
- ARP MITM Investigation - man-in-the-middle attack detection and credential theft analysis
- DNS Tunneling Detection - identifying data exfiltration via DNS queries
- Log4j Attack Detection - detecting Log4j RCE exploitation attempts
- Protocol Filters - DNS, HTTP, and TCP port analysis
- Reconstructing PDF from Base64 - CyberChef recipe for decoding and analyzing encoded files
- Threat Intelligence Challenge - independent file analysis and hash reputation lookup
- Linux and Bash Scripting - flag hunting, log searching, and system automation scripts
- FTP Enumeration - file transfer protocol reconnaissance and flag retrieval
- Nmap Web Enumeration - service detection and web server identification
- POP3 Enumeration - email protocol reconnaissance
- Telnet HTTP - legacy protocol analysis and HTTP communication
- TryHackMe SOC Level 1: In progress (~25+ labs completed)
- Certifications: Google Cybersecurity Certificate (completed), Security+ (in progress), Level 4 IT
- Homelabs: Windows Server, PowerShell scripting, system administration practice
- Real-world experience: 2 weeks shadowing a senior systems administrator
- Complete TryHackMe SOC Level 1 certification
- Pass CompTIA Security+ exam
- Transition into a Junior SOC Analyst or IT Support role