Mimikatz & PowerShell Investigation
Investigated suspicious endpoint activity involving credential-access behavior and PowerShell execution.
- Alert triage and process analysis
- Credential-access indicators
- Classification and escalation
SOC ANALYST • TIER 1 / JUNIOR SECURITY
Hands-on cybersecurity portfolio focused on alert triage, log analysis, phishing investigations, endpoint telemetry, PowerShell analysis, IOC correlation, incident classification, and escalation.
INVESTIGATION PORTFOLIO
Each case follows an analyst workflow from alert review through evidence correlation, classification, and response recommendations.
Investigated suspicious endpoint activity involving credential-access behavior and PowerShell execution.
Analyzed authentication telemetry to identify repeated failures, successful logons, suspicious source activity, and possible compromise.
Correlated suspicious email, DNS, proxy, message-trace, and identity-sign-in telemetry to assess user impact and compromise.
Investigated encoded PowerShell execution, payload retrieval, suspicious child processes, DNS/network activity, and malicious synthetic IOCs.
CAPABILITIES
Severity assessment, alert validation, evidence collection, classification, escalation.
Windows Security Events, authentication logs, process telemetry, DNS, proxy, message trace, identity sign-ins.
Process-tree investigation, parent-child relationships, command lines, PowerShell, file and hash review.
IOC correlation, suspicious IP/domain analysis, phishing artifacts, discovery activity, timeline reconstruction.
Python, grep, CSV/JSON parsing, Base64 decoding, filtering, correlation, and report generation.
Case summaries, findings, evidence chains, remediation recommendations, analyst verdicts, and escalation notes.
METHODOLOGY
Review alert, severity, affected user/host, detection source, and initial indicators.
Gather process, authentication, DNS, network, file, email, and identity telemetry as appropriate.
Connect events across data sources to establish an evidence-backed timeline.
Determine whether the alert is benign, suspicious, or a true-positive incident.
Document findings, recommend containment, and escalate when the incident exceeds L1 scope.
ABOUT THIS PORTFOLIO
These investigations demonstrate practical Tier 1 SOC skills using controlled training environments, lab-generated telemetry, and synthetic security data. The emphasis is on analyst methodology: understanding what happened, validating evidence, documenting findings, and knowing when to escalate.
Lab disclaimer: no production systems or real malicious infrastructure were accessed in the synthetic cases.
Review the full repository →