ISC2 CC | Building toward Tier 1 SOC and Detection Engineering | Hands-on investigations with Splunk, Wazuh and Sigma | Documenting what I learn

Johannesburg, South Africa
I’m building in public toward Tier 1 SOC and Detection Engineering roles. I share: Home lab builds Alert triage and investigations SIEM, EDR and network telemetry Detection logic and troubleshooting No production claims. Just evidence of what I’m learning, testing and building.
9
12
139
5,480
Your banking app does not need direct access to the bank's database to show your balance. It communicates through an API. An API lets applications exchange data and request services. But every API endpoint needs proper security. Convenience should never mean unrestricted access
1
24
Your password gets you through the login. But what gives an application permission to access your data afterward? An access token. It carries authorization information for specific resources. If stolen, it can give attackers access within its permissions.
1
12
318
William | SOC and Detection Engineering retweeted
What if an attacker does not need your password because they stole your active session? That is session hijacking. It happens when an attacker obtains a valid session and uses it to impersonate you. Sometimes stealing the session is enough.
2
4
13
358
William | SOC and Detection Engineering retweeted
RAM is one of the most valuable evidence sources in DFIR, especially during a live incident. In many investigations, memory can contain evidence that will disappear permanently the moment the computer is powered off or restarted. Think of RAM as the computer’s live workspace. The hard drive tells you a lot about what happened historically; RAM can tell you what is happening right now. A simple example: imagine an attacker compromises a Windows workstation using PowerShell and launches a reverse shell entirely in memory. There may be no obvious malware executable on the disk. If the investigator shuts the computer down before collecting RAM, some of the strongest evidence could disappear. This is why DFIR commonly follows the Order of Volatility: CPU/register/cache → RAM → active network connections/processes → temporary files → disk → remote logs/backups. In practice, RAM is usually acquired before shutting down a compromised machine when operational and legal considerations permit. Common memory-forensics tools include Volatility 3, WinPmem, Magnet RAM Capture, FTK Imager, DumpIt, Belkasoft RAM Capturer, and similar trusted acquisition tools.
4
25
1,357
William | SOC and Detection Engineering retweeted
Logging in is only the first step. How does an application remember that you already proved who you are? An authentication token can provide that proof after authentication. Protect the token. If someone steals it, they may not need your password.
4
12
196
William | SOC and Detection Engineering retweeted
There are other entry-level roles worth going after besides a SOC Analyst.
1
10
370
William | SOC and Detection Engineering retweeted
Day 31 & 32/90 of My Cybersecurity Learning Journey 🔐 The past two days have been about Reconnaissance, OSINT and getting more hands-on with Kali Linux. I learned how reconnaissance helps build a picture of what is publicly exposed before moving into active testing.
2
1
4
75
William | SOC and Detection Engineering retweeted
One of the biggest mistakes I see in many Ghanaian banks is the overreliance on GRC-driven security strategies. Some CISOs and CIOs are quick to approve budgets worth millions of cedis for security products and platforms, yet give little attention to manual security testing. Most of them often invest millions of cedis in security products, yet overlook the critical value of manual penetration testing, Forensics investigations and hands-on security validation. They invest because GRC says so; mostly not because is the right thing to do. There are little or no technical people in there. Most works are outsourced. This is why many CISOs and CIOs get misled sometimes. A vulnerability assessment report is presented to them as a penetration test report, and they accept it without question😂😂. Security tools are important, but they are not a silver bullet. The threat landscape today is evolving rapidly, and many of today's vulnerabilities, misconfigurations, and attack paths can only be uncovered through skilled manual assessment.
Replying to @RedHatPentester
One day we will talk about those organizations who just buy bunch of security tools to tick compliance checkbox 😆
4
8
49
4,248
I’m about to take another 100 practice questions before I sleep. I’m not just counting correct answers anymore. I’m studying WHY I get things wrong and where my thinking breaks down. That’s where I’m seeing my progress. What are you working on tonight?
7
5
37
554
William | SOC and Detection Engineering retweeted
Installing Windows Server was the easy part. Deciding what this machine was going to become was more important. Part 13 of rebuilding my SOC home lab. The isolated network was ready, so I started putting actual systems inside it. First up: DC01.
2
8
18
541
William | SOC and Detection Engineering retweeted
An alert tells you where to start looking. It doesn’t tell you what happened. That’s where the investigation starts.
3
7
200
William | SOC and Detection Engineering retweeted
Replying to @WilliamInCyber
I wanna be so good in cybersecurity Especially soc analyst That's all my desire
1
1
1
46
William | SOC and Detection Engineering retweeted
Getting into digital forensics is one thing. Learning how to think like a forensic examiner is another. I spoke about the journey, the mindset and the technical side of digital forensics with Deogratius Okello on The Cyber Weekly.
3
9
480
William | SOC and Detection Engineering retweeted
The world is round. And the place that might seem like the end, might also be the beginning.
1
1
81
William | SOC and Detection Engineering retweeted
Today I learnt about the OWASP Top 10: 2025. the most critical web application security risks right now. Not just memorizing the list, but understanding how these vulnerabilities happen and how attackers can abuse them.
Just learned about the DOM (Document Object Model) today. It converts HTML into a tree of objects that JavaScript can easily read and manipulate. 👇
3
14
304
Funny enough, the more tools I touch in my SOC lab, the more they keep sending me back to the basics. Not because I forgot them. Because I’m finally seeing why they matter. Actually building and investigating exposes gaps very quickly.
1
3
16
394
The questions becoming more valuable are: What should normally happen here? What changed? Why was this event generated? What evidence would confirm what I think happened? The fundamentals help me answer those questions. The tool helps me find the evidence.
1
1
2
25
The questions becoming more valuable are: What should normally happen here? What changed? Why was this event generated? What evidence would confirm what I think happened? The fundamentals help me answer those questions. The tool helps me find the evidence.
15
William | SOC and Detection Engineering retweeted
Cybersecurity capstone, Task 2: Kali and Ubuntu VMs talking to each other. What tripped me up: Default NAT isolates VMs. A NAT Network fixed it. SSH was installed on Ubuntu but switched off. Ping 0% loss, SSH login works. Nmap scans are next.
2
2
9
74