// defensive security operations

blue team operations
& SOC analysis

Over 118 live security alerts investigated, triaged, and documented — each one mapped to known attacker behaviour and written up with full methodology. 174+ completed lab scenarios covering network forensics, malware analysis, cloud intrusions, and incident response. Everything on this site is real work, publicly linked, and verifiable.

174
Total Labs
118
Investigations
CDSA
Certified
BTL1
Certified
SAL1
Certified
// live platform stats
HackTheBox Profile
// competitive rankings
snapshot history ›
blue team labs online
inksec
Junior Defender
1280
Points
#6
Global
#2
AU Rank
26 Jul 2026 · Forum Breach
cyberdefenders
@inksec
Pro
1273
Points
#4
Global
#1
AU Rank
28 Jul 2026 · breakout-daedalus
blueteamlabs.online · cyberdefenders.org snapshot-based ›
// portfolio at a glance
174
Labs
118
SOC Alerts
86.4%
TP Rate
9
CVEs
view full breakdown →
Auto-generated from 118 documented investigations — tools used, malware families, MITRE coverage, CVEs, attack patterns. The actual writeups, certs, and daily work are below.
// featured achievements
LetsDefend · Completed Pathway
SOC Analyst Learning Path
Certificate of Completion · February 2026
  • Real-world SIEM alert triage
  • Log analysis & correlation
  • Malware investigation & IOC identification
  • Incident documentation & reporting
  • Threat intelligence integration
view dashboard → certificate →
Level Effect · Certification
Certified Detection Engineer & Threat Hunter (CDETH)
Certified July 2026 · 16 Instructor-Reviewed Challenges
  • Alert classification — true positive / false positive with written justification
  • Regex pattern construction with detection-logic explanations
  • YARA rule authoring against real indicators of compromise
  • Sigma rule writing & tuning with detection logic explanations
  • Adversary emulation testing across MITRE ATT&CK TTPs
verify credential →
LetsDefend · Skill Path Complete
Malware Analysis Skill Path
Certificate of Completion · July 2026
  • Static & dynamic malware analysis
  • Sample triage & IOC extraction
  • Behavioural analysis in a sandbox
  • Malware classification & reporting
certificate →
CyberDefenders · Completed Track
SOC Analyst Tier 1
Completed April 2026 · 30 Investigations · 227 Questions
  • SIEM alert triage & log correlation
  • Network forensics & PCAP analysis
  • Memory forensics & disk image analysis
  • Threat intelligence & IOC attribution
  • Incident response & malware investigation
verify achievement →
CyberDefenders · In Progress
SOC Analyst Tier 2
Active lab grind · Endpoint & Memory Forensics focus
  • Memory forensics & volatile data analysis
  • Disk image forensics & file recovery
  • Malware triage & static analysis
  • Threat actor attribution & TI correlation
  • Advanced incident response workflows
TryHackMe · Certification
Security Analyst Level 1 (SAL1)
Certified April 2026 · Credly Verified
  • Alert triage & log analysis across SOC scenarios
  • PCAP investigation & network forensics
  • Threat intelligence & IOC correlation
  • Incident response workflows
  • Defensive reasoning & escalation methodology
verify on credly →
Level Effect · Certification
Cyber Defense Certified Analyst (CDCA)
Certified July 2026 · Fully Practical, No Multiple Choice
  • Live Virtual SOC alert queue — Tier 1 through Tier 2 investigations
  • Network traffic analysis, email/header analysis, live Windows host triage, SIEM log hunting
  • DFIR methodology, timeline construction, playbook-driven investigation
  • Capstone incident report — IOC documentation, executive summary, technical analysis, remediations
  • Graded, section-by-section manual review — no automated scoring
verify credential →
// youtube · daily grind
Day X: becoming a SOC analyst

One real LetsDefend alert per day, triaged out loud on camera. Structured workflow, log correlation, containment decisions — real analyst thinking documented publicly.

Format
Real alert → triage → log analysis → IOC correlation → containment decision → escalation or close. Every step narrated, every tool explained.
Also on YouTube
TryHackMe SAL1 walkthroughs · BTL1 lab investigations · platform-agnostic SOC methodology.
LetsDefend SOC Investigations
LetsDefend SOC Investigations
129 videos · 35+ hours
// youtube · cyberdefenders walkthroughs
Week X of DFIR

Full CyberDefenders lab walkthroughs on YouTube — every question answered, every tool and technique explained from scratch. Endpoint forensics, malware analysis, and threat investigation.

Format
One CyberDefenders lab per week. Full uncut walkthrough — artifact collection, tool usage, IOC extraction, and question-by-question reasoning explained out loud.
Coverage
Endpoint forensics · Malware analysis · Threat intelligence · Sysmon & evtx triage · .NET decompilation · C2 attribution
ContainerBreak - Rootkit Trail
ContainerBreak - Rootkit Trail
Week 7 · Easy · [Endpoint Forensics]
Stolen Time - HiddenTear
Stolen Time - HiddenTear
Week 6 · Medium · Threat Hunting
view all DFIR episodes →
// daily soc practice · live investigation log
daily investigations

Every alert triaged, documented, and mapped to MITRE ATT&CK. Updated daily as part of the Day N of Becoming a SOC Analyst series.

118
Investigations
102
True Positives
95
MITRE Techniques
16
Critical
Latest: SOC235 — Confluence Broken Access Control 0-Day C…
view full investigation log →
// kc7 · reusable detection patterns
kql pattern bank

Reusable KQL detection patterns auto-extracted from KC7 lab investigations — write the writeup once, every tagged query promotes itself into a searchable reference. Capability over completion: the queries are the takeaway.

9
Patterns Banked
5
Categories
6
ATT&CK Techniques
1
Source Labs
Categories: c2 · email · exfil · process · timeline
view the kql bank →
// mitre att&ck enterprise · technique coverage
att&ck heatmap

Every technique observed across labs and investigations mapped to MITRE ATT&CK Enterprise. Generated live from documented writeups — no manual curation.

400
Observations
94
Unique Techniques
14
Tactics Covered
T1105
Most Observed
explore full att&ck matrix →
// selected investigations
featured writeups

Twelve investigations selected across core blue team disciplines. Hard-rated labs, real artefacts, documented methodology.

incident response
digital forensics & reverse engineering
soc operations & threat intelligence
cloud forensics & investigation
malware analysis & reverse engineering
// all completed labs
lab grid

All platforms, all labs. Filter by platform, difficulty, or category. Adding new labs weekly.

skill
diff
showing 0 labs
no labs match that filter.
// active labs
active labs

Writeups are complete but locked until these labs officially retire. Reach out if you need the password.

// hackthebox sherlocks · dfir investigations
sherlock writeups

HTB Sherlocks — DFIR investigations covering endpoint forensics, threat intelligence, network analysis, and memory forensics.

// active sherlocks
active sherlocks

Writeups complete but locked until these sherlocks officially retire. Reach out if you need the password.

// challenges
challenge log

Shorter CTF-style challenges. Same platforms, less depth.

// home lab infrastructure
lab environments
📡
Splunk Enterprise SIEM
Production-style SIEM for alert detection, log analysis, and threat hunting.
Host:Ubuntu 24.04 · Splunk Enterprise
Agent:Windows 11 · Universal Forwarder
Telemetry:Sysmon event collection & parsing
Use Cases:Detection rules · SPL queries · dashboards
🦠
Malware Analysis Sandbox
Isolated environment for safe detonation, static analysis, and reverse engineering.
Platform:FlareVM · isolated virtual network
Tools:IDA · Ghidra · PE analysis · debuggers
Analysis:Static & dynamic examination
Use Cases:IOC extraction · behaviour analysis
🏠
Home Lab — Full Stack
pfSense + Security Onion + Splunk + Active Directory environment for realistic detection practice.
Network:SPAN mirroring · network segmentation
Detection:Zeek · Suricata · Splunk dashboards
AD Lab:Windows domain · attack simulation
Platform:CachyOS · virtualisation workstation
// investigation documentation
documentation & profiles
🗂️
Alert Triage Log
Every SOC investigation documented — dated, MITRE ATT&CK mapped, and publicly queryable. Updated daily.
  • 118 investigations logged & counting
  • 102 true positives · 16 false positives
  • 95 unique MITRE ATT&CK techniques observed
  • Latest: SOC235 — Confluence Broken Access Control 0-…
view full log →
⌨️
Command Reference
Every command used across real lab investigations — searchable, filterable, and copyable. Built so future me doesn't have to google the same thing twice.
  • 26 commands and growing
  • Volatility · Splunk · Wireshark · Zeek
  • Linked back to source lab for context
  • Auto-extracted from investigation notes
view command reference →
🔗
Public Platform Profiles
Verified investigation work across multiple SOC training platforms — all publicly verifiable.
  • LetsDefend — 34 cases, 97% success
  • TryHackMe — 46 cases, 100% detection
  • GitHub — full writeup repository
  • Real-time metrics & platform rankings
view leaderboard history →
✍️
Writing
Exam reviews, milestone reflections, and methodology notes — things that don't fit neatly elsewhere but are worth writing down.
  • BTL1 exam review — preparation & lessons
  • Day 100: reflections on daily alert triage
  • Not a blog. Just writing.
read →