Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
-
Updated
Mar 16, 2026 - HTML
Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
Curated Blue Team toolkit for defensive cybersecurity: asset discovery, vulnerability management, network monitoring, DFIR, threat intelligence, cryptography, endpoint security and SIEM/log management.
Email Header Forensics Lab is a desktop application for inspecting, generating, editing, and analyzing email headers in controlled environments for forensic analysis, security research, and authentication testing.
Phishing email investigation with full header analysis, link inspection, red-flag detection.
Comprehensive phishing incident response simulation with email forensics, threat intelligence enrichment, and NIST-aligned playbook
SOC-focused phishing investigation lab demonstrating OSINT analysis, IOC extraction, domain intelligence validation, and MITRE ATT&CK mapping.
Phishing triage analysis of a real Sneaky2FA AiTM campaign targeting Microsoft 365. Documents the full attack chain, IOC extraction, evasion techniques, and sandbox vs reputation tool detection gap.
Network traffic analysis and phishing investigation project focused on TCP SYN scan detection, threat analysis, and cybersecurity incident identification.
Hands on analysis and defending against phishing emails. Investigating real-world phishing attempts using a variety of techniques.
Modular SOC analyst toolkit with phishing email analyzer, log parser, and IOC extractor. Built with FastAPI + React, integrates VirusTotal, AbuseIPDB, Shodan, URLScan.io, and AlienVault OTX APIs
A full phishing investigation of a cryptocurrency themed scam email containing a malicious PDF and Bitly redirect. Includes header analysis, attachment analysis, IOCs, MITRE ATT&CK mapping, and a SOC level risk assessment.
OSINT-driven analysis of a Trustwallet phishing campaign — infrastructure, lures, and indicators of compromise.
TrustNoChar is a zero-dependency browser-based lab that demonstrates how Unicode homoglyphs and typosquatting attacks exploit human visual perception. It transforms text into deceptive lookalike variants in real time to help researchers, red teams, and security learners study phishing, rendering quirks, and cognitive security risks. 🛡️👁️
Simulation and analysis of phishing emails — headers, payloads, and attacker techniques.
Forensic analysis of a targeted phishing campaign, email header tracing, URL sandboxing, and IOC extraction.
Blue Team investigations including browser threat hunting, phishing analysis, and SIEM alert triage. Saviva~
Cybersecurity portfolio with hands-on blue team, web security, and beginner pentesting projects.
Phishing analysis lab using PhishTank, VirusTotal, MXToolbox, and PhishTool to investigate 3 live phishing URLs and 2 phishing emails targeting cryptocurrency users. Covers URL analysis, email header analysis, SPF/DKIM/DMARC authentication, and campaign correlation.
Practical phishing email investigation lab using Thunderbird, email headers, URL/domain analysis, IOC documentation and SOC-style reporting.
Executive phishing email analysis for VitalCare Health Solutions – includes header inspection, BEC indicators, SPF/DKIM/DMARC checks, malicious attachment & URL analysis, and a stakeholder-ready executive report with findings, impact, and recommendations.
Add a description, image, and links to the phishing-analysis topic page so that developers can more easily learn about it.
To associate your repository with the phishing-analysis topic, visit your repo's landing page and select "manage topics."