Investigation Portfolio

Threat Investigations

Structured cyber threat investigations completed using realistic enterprise scenarios from the KC7 Cyber Security Analyst program. Each report documents analytical methodology, evidence collection, KQL investigations, IOC analysis, MITRE ATT&CK mapping, and investigation findings. These are scenario-based investigations developed in a training environment — not real-world client engagements.

Financial Services Insider Threat → AD Ransomware

Inside Encryptodera: An Insider Threat Scenario

A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to a domain-wide Active Directory...

ATT&CK · 8 Confidence · High 9 min read Completed
Insider ThreatActive Directory Ransomware
Energy / Critical Infrastructure (ICS) Supply-Chain Espionage

Solvi Systems: A tale of Supply Chains and ICS

Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code exfiltration using raw web...

ATT&CK · 8 Confidence · High 11 min read Completed
Critical InfrastructureSupply Chain
Public Sector / Elections APT In Progress

Valdoria Votes: Advanced Persistent Threat Analysis

Investigating a high-stakes, state-sponsored campaign targeting election infrastructure. Reconstructing attacker persistence mechanisms, multi-hop C2 structures, and domain registrar anomalies.

Coming Soon
APT CampaignInfrastructure Tracking
Coming soon