Investigation Portfolio

Threat Investigations

Structured cyber threat investigations completed using realistic enterprise scenarios from the KC7 Cyber Security Analyst program. Each report documents analytical methodology, evidence collection, KQL investigations, IOC analysis, MITRE ATT&CK mapping, and investigation findings. These are scenario-based investigations developed in a training environment not real-world client engagements.

View my KC7 Cyber profile →

Financial Services Insider Threat → AD Ransomware

Inside Encryptodera: An Insider Threat Scenario

A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to a domain-wide Active Directory...

ATT&CK · 8 Confidence · High 9 min read Completed
Insider ThreatActive Directory Ransomware
Energy / Critical Infrastructure (ICS) Supply-Chain Espionage

Solvi Systems: A tale of Supply Chains and ICS

Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code exfiltration using raw web...

ATT&CK · 8 Confidence · High 11 min read Completed
Critical InfrastructureSupply Chain
Public Sector / Elections APT Part 1 Published

Valdoria Votes: Advanced Persistent Threat Analysis

Part 1 of a two-part, scenario-based investigation into a multi-stage social-engineering campaign against The Valdorian Times. Reconstructs weaponized recruitment lures, scheduled-task persistence, automated plink.exe reverse-SSH tunneling, 7-Zip data archival and...

ATT&CK · 7 Confidence · High 8 min read Part 1 Published
APT CampaignInfrastructure Tracking