Documented walkthroughs of blue team challenges I've completed — investigation methodology, findings, and lessons learned. Written to reinforce my own process and track progress as I build toward a SOC analyst role.
Each write-up follows the same structure: scenario, objective, methodology, key findings, and lessons learned — not just the answer, but how I got there.
| Challenge | Write-up |
|---|---|
| Bluesky Ransomware | View Write-up |
| Openwire | View Write-up |
| Packetmaze | View Write-up |
| Retailbreach | View Write-up |
| Tomcat Takeover | View Write-up |
| Challenge | Write-up |
|---|---|
| Log Analysis Sysmon | View Write-up |
| Network Analysis Web Shell | View Write-up |
| Phishing Analysis 2 | View Write-up |
| Phishing Analysis | View Write-up |
| The Report | View Write-up |
Every challenge write-up follows this template:
# Challenge Name — Platform
## Scenario
The premise, in my own words.
## Objective
What I was asked to find or determine.
## Methodology
The actual investigation steps, in order.
## Key Findings / IOCs
Attacker IPs, payloads, techniques, artifacts.
## Lessons Learned
What this taught me, what I'd do differently.Part of my self-directed SOC analyst training, alongside a home lab running Wazuh and Suricata (soc-blue-team-lab) and ongoing certification prep.