Finding a 90-day phishing campaign behind one quiet email
A quarantined email passed SPF/DKIM and sandbox detonation and carried no links or attachments. Pivoting on it uncovered a 90-day, multi-domain reply-bait campaign.
What I do when something is actually wrong: triage the alert, find out what is really happening, and contain it in a way the business can live with.
A quarantined email passed SPF/DKIM and sandbox detonation and carried no links or attachments. Pivoting on it uncovered a 90-day, multi-domain reply-bait campaign.
Internet-exposed production servers at 100% CPU, with isolation ruled out by uptime requirements. Baselining against a known-good host exposed masquerading malware; a default-deny egress firewall cut C2 and XMRig mining traffic.
Drawn from those two cases, not a generic playbook.
As a SOC Analyst Trainee at SOCByte, February – April 2026.
Every incident ends in a timeline. I built a small incident timeline builder that runs entirely in your browser and exports Markdown, CSV, or JSON.