Cyber Threat Intelligence
Collect, analyze, and report structured intelligence on threat activity, tradecraft, indicators, and investigative findings.
Cyber Threat Intelligence · Threat Hunting · Dark-Web Research
I'm Joshua Berkoh — a cybersecurity professional and PhD researcher working in threat investigations, threat hunting, and dark-web intelligence research. Through scenario-based investigations and security research, I reconstruct intrusion activity, map observed tradecraft to MITRE ATT&CK, and turn raw telemetry into clear, defensible intelligence.
MITRE ATT&CK · KQL · OSINT · IOC Pivoting · Threat Hunting · Python · Graph Analysis
Capabilities
Demonstrated competencies across the intelligence cycle — collection, analysis, and reporting — grounded in completed investigative and research work.
Collect, analyze, and report structured intelligence on threat activity, tradecraft, indicators, and investigative findings.
Hypothesis-driven hunts across endpoint and network telemetry using KQL and ATT&CK.
End-to-end intrusion reconstruction — timelines, evidence, IOCs, and assessments.
Research into anonymity networks, hidden services, and underground infrastructure.
Structured analytic methods, source evaluation, and confidence-based judgments.
Tooling, measurement, and methodology that extend how threats are studied.
Investigations
Threat-investigation case studies: full intrusion reconstructions with timelines, IOC analysis, and MITRE ATT&CK mapping. Developed from KC7 threat scenarios and written to professional intelligence-reporting standards.
A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to...
Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code...
Investigating a high-stakes, state-sponsored campaign targeting election infrastructure. Reconstructing attacker persistence mechanisms, multi-hop C2 structures, and domain registrar anomalies.
Research
An intelligence-collection lens on anonymity infrastructure: discovering hidden services, mapping the relationships between them, and measuring how the ecosystem behaves at scale.
I'm building a cross-layer framework that fuses network-layer routing data with application-layer hidden-service ("eepsite") crawls into a single graph — making it possible to study anonymity infrastructure and the services riding on it as one connected hidden-service ecosystem. The work spans hidden-service discovery, infrastructure mapping, large-scale collection, and graph analysis.
Explore the research →Lab activity
A working record of what I'm building now and how the lab is growing over time.
Currently working on
Timeline
Publications
Finished intelligence products and research output — investigation reports, research papers, and technical articles.
Published investigation reports are listed under Investigations; academic and research output is collected on the Publications page.
View publications →About
I'm a PhD researcher in Information Technology and a practicing security professional. My work sits where intelligence analysis meets hands-on investigation: reconstructing intrusions, hunting for adversary activity in telemetry, and researching the infrastructure that threats rely on. I've served as a SOC analyst defending financial institutions and as a security engineering intern, and I hold hall-of-fame recognition from multiple bug-bounty programs.
I write every investigation to be defensible — evidence-first, mapped to MITRE ATT&CK, and honest about confidence. Detection engineering is an area I'm actively studying and will publish as the work matures.
More about me →Contact
If your team works in cyber threat intelligence, threat hunting, or security research, I'd welcome a conversation.