SOC ANALYST • TIER 1 / JUNIOR SECURITY

Akachi Maduako

Hands-on cybersecurity portfolio focused on alert triage, log analysis, phishing investigations, endpoint telemetry, PowerShell analysis, IOC correlation, incident classification, and escalation.

4Case Studies
L1SOC Focus
SIEM + EDRInvestigation Skills

INVESTIGATION PORTFOLIO

Hands-on SOC case studies

Each case follows an analyst workflow from alert review through evidence correlation, classification, and response recommendations.

01
Credential AccessPowerShell

Mimikatz & PowerShell Investigation

Investigated suspicious endpoint activity involving credential-access behavior and PowerShell execution.

  • Alert triage and process analysis
  • Credential-access indicators
  • Classification and escalation
Open case study →
02
AuthenticationBrute Force

Brute-Force Investigation

Analyzed authentication telemetry to identify repeated failures, successful logons, suspicious source activity, and possible compromise.

  • Windows Security Event analysis
  • Failed vs successful logon correlation
  • Source IP and host timeline review
Open case study →
03
PhishingIdentity

Phishing & Credential Compromise

Correlated suspicious email, DNS, proxy, message-trace, and identity-sign-in telemetry to assess user impact and compromise.

  • Email-header analysis
  • DNS / proxy / sign-in correlation
  • IOC enrichment and timeline reconstruction
Open case study →
04
EDRMalware

PowerShell Malware Investigation

Investigated encoded PowerShell execution, payload retrieval, suspicious child processes, DNS/network activity, and malicious synthetic IOCs.

  • Process-tree analysis and Base64 decoding
  • DNS, network, file, and hash correlation
  • True-positive classification and L2 escalation
Open case study →

CAPABILITIES

SOC skills demonstrated

Alert & Incident Triage

Severity assessment, alert validation, evidence collection, classification, escalation.

Log Analysis

Windows Security Events, authentication logs, process telemetry, DNS, proxy, message trace, identity sign-ins.

Endpoint / EDR

Process-tree investigation, parent-child relationships, command lines, PowerShell, file and hash review.

Threat Investigation

IOC correlation, suspicious IP/domain analysis, phishing artifacts, discovery activity, timeline reconstruction.

CLI Analysis

Python, grep, CSV/JSON parsing, Base64 decoding, filtering, correlation, and report generation.

Documentation

Case summaries, findings, evidence chains, remediation recommendations, analyst verdicts, and escalation notes.

METHODOLOGY

How I investigate an alert

  1. 01
    Triage

    Review alert, severity, affected user/host, detection source, and initial indicators.

  2. 02
    Collect evidence

    Gather process, authentication, DNS, network, file, email, and identity telemetry as appropriate.

  3. 03
    Correlate

    Connect events across data sources to establish an evidence-backed timeline.

  4. 04
    Classify

    Determine whether the alert is benign, suspicious, or a true-positive incident.

  5. 05
    Respond

    Document findings, recommend containment, and escalate when the incident exceeds L1 scope.

ABOUT THIS PORTFOLIO

Built to show the work, not just list tools.

These investigations demonstrate practical Tier 1 SOC skills using controlled training environments, lab-generated telemetry, and synthetic security data. The emphasis is on analyst methodology: understanding what happened, validating evidence, documenting findings, and knowing when to escalate.

Lab disclaimer: no production systems or real malicious infrastructure were accessed in the synthetic cases.

Review the full repository →