Skip to main content
Blue Team Exercises & Investigations

Security Labs & Investigations

Practical security investigations, detection exercises, and lab write-ups documenting the evidence, tools, methodology, findings, and lessons from each exercise.

Training & Sandbox Environment Notice

All investigations documented below were conducted in dedicated, isolated training sandboxes or home lab environments. All indicators, usernames, and systems are simulated or sanitized.

Category:
Severity:
SOC-014·SOC·HighTrue PositiveTraining Lab
2026-09-12

Investigating Suspicious Encoded PowerShell Execution

Triage and root-cause analysis of an alert indicating an obfuscated Base64 PowerShell execution spawned by Microsoft Office in an isolated Windows endpoint.

Tools: Splunk Enterprise, Sysmon v15, CyberChef, VirusTotal, Procmon|Env: Windows 11 Enterprise (Isolated SOC Lab)
View full incident report
SOC-019·Linux·MediumTrue PositivePersonal Home Lab
2026-09-04

Triage of Distributed SSH Authentication Failures

Investigation of over 12,000 failed SSH authentication attempts on an internet-facing Linux bastion host, identifying dictionary brute-force patterns and misconfigured firewall rules.

Tools: rsyslog, grep/awk/sed, Fail2ban, GeoIP CLI, Wireshark|Env: Ubuntu 24.04 LTS (Cloud VPS Bastion)
View full incident report
Lab Safety & Ethics Notice

All investigations published here were conducted in isolated sandboxes, dedicated virtual test machines, or authorized training subnets. Sensitive organizational identifiers and IP ranges are sanitized.