Incident response

What I do when something is actually wrong: triage the alert, find out what is really happening, and contain it in a way the business can live with.

Two incidents I helped work

  • Past workIncident response

    Finding a 90-day phishing campaign behind one quiet email

    A quarantined email passed SPF/DKIM and sandbox detonation and carried no links or attachments. Pivoting on it uncovered a 90-day, multi-domain reply-bait campaign.

    PhishingEmail securityThreat huntingSOC
  • Past workIncident response

    Containing a server compromise without taking production down

    Internet-exposed production servers at 100% CPU, with isolation ruled out by uptime requirements. Baselining against a known-good host exposed masquerading malware; a default-deny egress firewall cut C2 and XMRig mining traffic.

    Incident responseWindowsCrowdStrikePowerShell

How I approach an investigation

Drawn from those two cases, not a generic playbook.

  1. Establish what normal looks likeA known-good host showed which processes were out of place. Masquerading works on names; it rarely survives a comparison of paths.
  2. Pivot on what you haveA sender alias, a source IP, and a subject line turned one email into a 90-day campaign.
  3. Validate before actingCheck hashes and indicators before blocking, and treat a clean reputation score as a data point rather than a verdict.
  4. Contain within the constraintWhen servers cannot go offline, choose the control that stops the threat without stopping production.
  5. Close the loopRetro-hunt, block related infrastructure, tell the people affected, and report gaps to the vendor.

Day-to-day SOC work

As a SOC Analyst Trainee at SOCByte, February – April 2026.

  • Performed L1 monitoring and alert triage across SIEM/XDR/NDR platforms (Wazuh, QRadar, Rapid7 InsightIDR, Trend Micro Vision One, Vectra AI) and EDR (CrowdStrike), escalating confirmed incidents per playbooks.
  • Monitored WAF events and HTTP logs for common web attacks such as SQL injection patterns, validating findings and recommending blocks.
  • Operationalized threat intelligence by curating and blocking IOCs (URLs, domains, hashes) in MISP, based on Group-IB and CTM360 feeds and reports.
  • Investigated active alerts by validating evidence (process and user activity, network indicators, timelines) to support accurate escalation.

A tool for the write-up

Every incident ends in a timeline. I built a small incident timeline builder that runs entirely in your browser and exports Markdown, CSV, or JSON.

Search the site