-
SOC Investigation Case Study โ Credential Phishing and Microsoft 365 Account Compromise
๐งช SOC Phishing Case #003 โ Credential Phishing + Possible Account Compromise Overview This investigation analyzes a phishing attack targeting an HR employee through a fake Microsoft password-expiration notification. Unlike a simple phishing attempt where a user clicks a malicious link but does not provide credentials, this case progressed fur... Read More
-
SOC Investigation Case Study โ Incident Scoping and Patient Zero
๐งช SOC Case #005 โ Incident Scoping & Patient Zero Overview This investigation focused on a different SOC question: How far did the attack spread? Rather than analyzing one suspicious event in isolation, the objective was to correlate email, endpoint, network, authentication and file-share telemetry across multiple workstations. The ... Read More
-
Soc Investigation Case Study Phishing Email Analysis
SOC Phishing Investigation โ Microsoft Account Verification Credential Phishing Analysis and Post-Click Investigation 1. Investigation Overview This case study presents a hypothetical SOC investigation involving a phishing email impersonating Microsoft Security. The exercise was designed to evaluate how a SOC analyst moves from: Suspiciou... Read More
-
Soc Investigation Legitimate Administration To Confirmed Compromise
Splunk SOC Investigation โ ITSupport02: From Legitimate Administration to Confirmed Compromise Overview This hypothetical SOC investigation examines activity involving ITSupport02 across CLIENT60, CLIENT61, DC01, and FILESERVER02. The exercise is designed around an important SOC challenge: legitimate administrative activity can closely resemb... Read More
-
Soc Investigation Helpdesk03 Legitimate Administration Vs Malicious Activity
Splunk SOC Investigation Case Study: HelpDesk03 โ Legitimate Administration or Compromise? Overview This case study documents a hypothetical SOC investigation designed to test the distinction between legitimate IT administration and potentially malicious activity. The investigation follows the activity of HelpDesk03 across CLIENT51, CLIENT50,... Read More
-
Soc Investigation The Missing Beginning
SOC Investigation Case Study: The Missing Beginning Overview This case study simulates a SOC investigation in which the beginning of an attack is not fully visible in the available telemetry. The objective was to investigate a sequence of Windows events involving: FinanceUser02 CLIENT31 CLIENT30 DC01 FILESERVER01 The investigat... Read More
-
Soc Investigation Case Study The Compromised Administrator
SOC Investigation Case Study โ The Compromised Administrator Investigation Objective This exercise simulates a potential compromise involving a privileged IT administrator account and multiple Windows systems. The objective was to determine where legitimate administrative activity transitioned into suspicious behavior, identify the point at ... Read More
-
Soc Investigation Case Study The Administrator And The Intruder
SOC Investigation Case Study โ The Administrator and the Intruder Mixed-Telemetry Investigation: Distinguishing Legitimate Administration from Active Compromise Overview This investigation was designed to simulate a realistic SOC scenario where legitimate administrative activity transitions into malicious behavior. The challenge was not sim... Read More
-
Soc Investigation Case Study Helpdesk
SOC Investigation Case Study: The HelpDesk Account Investigating Suspicious Active Directory Enumeration and Remote PowerShell Administration Overview This case study documents a simulated SOC investigation involving a legitimate-looking helpdesk account, HelpDesk01, performing Active Directory enumeration followed by remote PowerShell admi... Read More
-
SOC Case Study 01 โ The Silent Domain Admin
SOC Case Study 01 โ The Silent Domain Admin Investigating Active Directory Reconnaissance, Lateral Movement, and Suspected Data Exfiltration Overview This case study documents a simulated Security Operations Center (SOC) investigation in which multiple Windows Security Events, Sysmon logs and PowerShell telemetry were correlated to determine ... Read More
-
Splunk Powershell Event Correlation Lab
Splunk PowerShell Multi-Event Correlation Investigation Investigating PowerShell Web Requests Across Multiple Windows Event Sources Overview This project documents a hands-on SOC investigation focused on correlating PowerShell activity across multiple Windows telemetry sources using Splunk SIEM. The objective of the lab was to simulate sus... Read More
-
Splunk Powershell Scriptblock Logging Lab
Splunk PowerShell Script Block Logging Lab Detecting PowerShell Abuse Using Windows Event ID 4104 Overview This project documents a hands-on SOC detection lab focused on identifying suspicious PowerShell activity using Windows PowerShell Script Block Logging and Splunk. The objective of the lab was to understand how defenders investigate P... Read More
-
Splunk Service Persistence Detection Lab 7045 Investigation
Splunk Windows Service Persistence Detection Lab Detecting Malicious Service Creation Using Windows Event ID 7045 Overview This project documents a hands-on SOC detection lab focused on identifying malicious Windows service creation using Splunk and Windows Event Logs. The objective of the lab was to understand how attackers abuse Windows ... Read More
-
Splunk Scheduled Task Persistence Lab
Splunk Scheduled Task Persistence Detection Lab Detecting Windows Scheduled Task Persistence Using Event ID 4698 Overview This project documents a hands-on SOC detection lab focused on identifying Windows scheduled task persistence using Splunk and Windows Security logs. The objective of the lab was to understand how attackers abuse schedu... Read More
-
Splunk Runkey Persistence Detection Lab
Splunk Registry Run Key Persistence Detection Lab Detecting Windows Autorun Persistence Using Sysmon Event ID 13 Overview This project documents a hands-on SOC detection lab focused on identifying Windows persistence mechanisms using Sysmon registry monitoring and Splunk. The objective of the lab was to understand how attackers maintain ac... Read More
-
Splunk Powershell Network Corellation
Splunk PowerShell Network Correlation Lab Detecting Suspicious PowerShell Download Activity Using Sysmon and Splunk Overview This project documents a hands-on SOC detection lab focused on identifying suspicious PowerShell activity and correlating process creation events with outbound network connections using Splunk and Sysmon. The objecti... Read More
-
Splunk Process Tree Detection Lab
Splunk Process Tree Detection Lab โ Parent and Child Process Investigation Overview This lab focuses on process creation monitoring and process tree analysis using Splunk and Windows Security Event Logs. The objective of the lab was to understand how parent-child process relationships appear in Windows telemetry and how SOC analysts reconstru... Read More
-
Splunk Soc Practice And Detection
Beginner SOC Lab with Splunk โ Windows Log Analysis and Authentication Monitoring Overview This project documents my hands-on learning journey with Splunk as I practice core Security Operations Center (SOC) workflows in a virtual lab environment. The objective of this lab was to: Install and configure Splunk Enterprise Set up a small vi... Read More
-
Snort Custom Rule Detection Lab
Snort Custom Rule Detection Lab Overview This project demonstrates the creation and testing of custom intrusion detection rules using Snort in a controlled lab environment. The objective was to configure Snort to detect specific types of network traffic and generate alerts when those traffic patterns occur. Two detection scenarios were impleme... Read More
-
CompTIA Security+ Certification Milestone
Overview I am excited to share that I successfully passed the CompTIA Security+ certification exam with a score of 782. Security+ is a globally recognized cybersecurity certification that validates foundational knowledge across: Threat detection and response Network security Identity and access management Security architecture Cryptogra... Read More
-
Telecoms Network Bandwidth Planning
๐ก Telecom Transmission Planning & Aggregation Design Challenge Overview This project documents the solution to a telecommunications transmission planning challenge involving bandwidth calculation, Busy Hour Traffic (BHT) engineering, microwave backhaul dimensioning, redundancy planning, and future capacity growth. The objective was to desi... Read More
-
Malware Traffic Investigation Using Wireshark (PCAP Analysis)
Case Overview This investigation analyzes a packet capture file (2023-02-03.pcap) to identify suspicious activity, Indicators of Compromise (IOCs), and evidence of malware infection within a local network. The objective was to examine network traffic, trace malicious downloads, observe post-infection behavior, and determine the overall securit... Read More
-
Malware Traffic Analysis Using PCAP
๐ Download Full Report (PDF): Malware Traffic Analysis Report ๐ก Case Overview A packet capture file (2021-09-14.pcap) containing 3,679 packets was analyzed following reports that an endpoint device may have downloaded malware. The objective of this analysis was to identify suspicious network activity and extract potential Indicators of Compromi... Read More
-
Observing Plaintext HTTP Traffic Using Packet Capture
๐ Project Overview This lab demonstrates how HTTP traffic is transmitted in plaintext and can be observed using packet capture tools. The objective was to show why unencrypted protocols like HTTP present security risks, as sensitive data can be exposed during transmission. ๐ Full Technical Report: Download the Plaintext HTTP Traffic Analysis R... Read More
-
Network Packet Capture & TCP Handshake Analysis
๐ก Project Overview This project demonstrates practical network packet capture and TCP traffic analysis performed in a local lab environment using Kali Linux. The objective was to observe how systems communicate over TCP and understand how the three-way handshake establishes reliable connections. The lab involved setting up a local HTTP server ... Read More
-
SOC Email Analysis: Investigating a Suspicious Email
Introduction As part of my journey into Security Operations (SOC), I analyzed a suspicious email to identify potential phishing indicators. This post documents the investigation process and key observations from a SOC analyst perspective. Objective The goal of this analysis was to: Review email headers and metadata Identify spoofing or... Read More
-
How I've built my website
I created a GitHub account I forked a repository from https://github.com/datamaunz I renamed the forked repository precious-anyanwu.github.io I edited the files as described in the README.md Now I am writing my first post by following the advice that I got from the README file Read More
-
Introduction to Python
Introduction to Python This post is meant to summarize some of the key concepts I have learned in the course Introduction to Python Read More
-
Markdown Guide
Resources This is a good guide to learn about the basic markdown syntax. Read More
# Precious Anyanwu
**SOC & Cloud Security Enthusiast**
Linux โข AWS Security โข Security Monitoring โข Incident Analysis
---
## ๐ Welcome
I am an aspiring cybersecurity professional with a focused interest in **Security Operations (SOC)** and **Cloud Security**. I have a technical background in telecoms Radio Access Network (RAN) operations and data annotation for machine learning workflows.
My experience includes network monitoring, fault analysis, infrastructure awareness, and structured data labeling with strong attention to detail. I am currently building hands-on projects in Linux security, SOC-style email and log analysis, and AWS security configurations.
This site documents my learning journey, practical labs, and security-focused projects as I prepare for entry-level and junior SOC or Cloud Security roles.
---
## ๐ Areas of Focus
- SOC workflows and alert analysis
- Email and phishing investigation
- Cloud security fundamentals (AWS)
- Linux security and system monitoring
- Network traffic analysis for security
---
## ๐ Projects
Selected hands-on projects and labs:
- **SOC Email Analysis** โ Email header analysis and phishing investigation
- **AWS Security Fundamentals** โ IAM, logging, and monitoring
- **Linux Security Monitoring** โ System hardening and log analysis
(Full documentation available on my GitHub repositories.)
---
## ๐ซ Contact
- GitHub: https://github.com/precious-anyanwu
- LinkedIn: *(coming soon)*
---
# Feel free to add content and custom Front Matter to this file.
# To modify the layout, see https://jekyllrb.com/docs/themes/#overriding-theme-defaults
layout: home
title: Home
banner: "assets/images/banners/home.jpeg"
---