Cybersecurity Analyst · HX, UK

Bolaji Adetoye

I turn noisy alerts into clear answers. I triage, investigate, and write the detection that catches it faster next time.

Open to Tier 1 and Tier 2 SOC roles

How I work an alert

Four steps, every time

  1. Triage

    Read the alert, check severity and asset value, and decide in minutes whether it needs a deeper look.

  2. Investigate

    Pull the logs, build the timeline, and test each explanation until one fits the evidence.

  3. Respond

    Recommend containment, document indicators, and escalate with everything the next tier needs.

  4. Detect

    Write or tune a rule so the same behaviour is caught earlier and with less noise.

Case files

Investigations

Each case follows one alert from first triage to verdict. Open a case to see what fired, what I checked, and how it ended.

0012026-09-14

[Sample] Credential phishing with a lookalike sign-in page

A reported invoice email led to a fake Microsoft 365 login page hosted on a newly registered domain.

  • T1566.002
  • Email headers
  • URL sandbox
  • LetsDefend
TRUE POSITIVE+ Open case− Close

What fired

  • User report through the phishing button
  • Sender domain registered three days earlier

What I checked

  • Headers: SPF and DKIM both failed
  • Link detonated in a sandbox, credential form captured
  • Mail logs: 14 other recipients, 2 clicks

Outcome

  • Domain and sender blocked, emails purged
  • Password reset for both users who clicked
  • Indicators documented for the threat intel list
0022026-08-30

[Sample] Encoded PowerShell launched from a Word document

Sysmon showed winword.exe spawning PowerShell with a Base64 command that downloaded a second stage.

  • T1059.001
  • T1204.002
  • T1027
  • Sysmon
  • Splunk
TRUE POSITIVE+ Open case− Close

What fired

  • Process creation: Office parent, PowerShell child
  • Command line contained -EncodedCommand

What I checked

  • Decoded the payload and extracted the download URL
  • Mapped the full process tree from Sysmon Event ID 1
  • Confirmed the outbound connection in Event ID 3

Outcome

  • Host isolated, file hash blocked
  • Timeline written from document open to containment
  • New Sigma rule added (see Detections)
0032026-08-11

[Sample] Impossible travel alert explained by a corporate VPN

Sign-ins from two countries ten minutes apart looked like account takeover. The evidence said otherwise.

  • T1078
  • Entra ID logs
  • KQL
  • Alert tuning
FALSE POSITIVE+ Open case− Close

What fired

  • Identity protection: atypical travel, medium risk

What I checked

  • Same device ID and user agent on both sign-ins
  • Second IP matched a known VPN egress range
  • MFA satisfied, no mailbox rule changes afterwards

Outcome

  • Closed as false positive with evidence attached
  • Proposed tuning: exclude named VPN egress ranges
0042026-07-22

[Sample] DNS tunnelling found in a packet capture

Long, high-entropy subdomain queries to a single domain stood out against normal traffic.

  • T1071.004
  • T1048
  • Wireshark
  • CyberDefenders
TRUE POSITIVE+ Open case− Close

What fired

  • DNS query length anomaly on one workstation

What I checked

  • Query length and volume compared with a baseline
  • Subdomain labels decoded from Base32
  • Rebuilt part of the exfiltrated file

Outcome

  • Domain sinkholed, host sent for reimaging
  • SPL search written for long-query detection

Detection engineering

Rules I wrote

Each rule comes out of a case above. Replace these samples with rules you have tested in your own lab.

[Sample] Office application spawning PowerShell

From case 002. Any platform that reads Sigma.

title: Office Application Spawning PowerShell
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    ParentImage|endswith:
      - '\winword.exe'
      - '\excel.exe'
      - '\powerpnt.exe'
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
  condition: selection
falsepositives:
  - Legitimate macros run by finance or IT teams
level: high
tags:
  - attack.execution
  - attack.t1059.001

MITRE ATT&CK

Techniques I have investigated

Every technique here links back to a case number, so the coverage is backed by work you can read.

Initial access

T1566.002Spearphishing linkCase 001
T1078Valid accountsCase 003

Execution

T1059.001PowerShellCase 002
T1204.002Malicious fileCase 002

Defense evasion

T1027Obfuscated files or informationCase 002

Credential access

T1110.003Password sprayingKQL rule

Command and control

T1071.004DNSCase 004

Exfiltration

T1048Exfiltration over alternative protocolCase 004

Toolkit

What I work with

SIEM and log analysis

  • Splunk
  • Microsoft Sentinel
  • Wazuh
  • Elastic

Endpoint

  • Sysmon
  • Windows Event Logs
  • Microsoft Defender
  • Velociraptor

Network

  • Wireshark
  • Zeek
  • Suricata
  • tcpdump

Email and malware triage

  • Header analysis
  • Any.Run
  • VirusTotal
  • CyberChef

Query and scripting

  • KQL
  • SPL
  • Sigma
  • Python
  • PowerShell

Frameworks

  • MITRE ATT&CK
  • NIST incident response
  • Cyber Kill Chain
Security+CompTIA[Year earned]
CySA+CompTIA[Year earned]
BTL1Security Blue Team[Year earned]
SC-200Microsoft[In progress]

Home lab

Where the cases come from

An isolated virtual network where I run attacks, collect the logs, and test every rule before it goes on this site.

Attack

Kali Linux

Atomic Red Team tests and manual techniques

Targets

Windows 11, Ubuntu

Sysmon and auditd on every host

Collect

[Wazuh or Splunk]

Endpoint, DNS, firewall, and sign-in logs

Detect

Rules and dashboards

Alerts feed the cases on this page

Let's close some alerts.