SOC investigations

Windows security log analysis

A growing collection of evidence-led investigations using Windows Event Logs and Sysmon telemetry.

Windows Intrusion Investigation

Reconstructing a brute-force RDP compromise, backdoor account creation, privilege escalation, malware delivery, persistence, and command-and-control activity.