Long-form
Blog
Original writing, separate from dev.to. Longer explorations, working notes, and things that don't fit in a short-form article.
SOC176 | RDP Brute Force Detected
Platform: LetsDefend Date Investigated: March 07, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary On March 7, 2024 at 11:44 AM, an alert fired after multiple f
SOC205 | Malicious Macro Has Been Executed
Platform: LetsDefend Date Investigated: February 28, 2024 Severity: Medium Verdict: True Positive ✅ Actions Taken: Endpoint contained Summary A malicious Word document disguised as an invoice was deli
SOC338 | Lumma Stealer, DLL Side-Loading via ClickFix Phishing
Platform: LetsDefend Date Investigated: March 13, 2025 Severity: Critical Category: Data Leakage Verdict: True Positive ✅ Actions Taken: Email deleted, endpoint contained Summary A phishing email impe
Coming Back to Writing = and My First Cybersecurity Project
It's been a while since I've written anything publicly. I used to be fairly active documenting what I was building as a developer, and somewhere along the way - between shipping products and then pivo
Second Project Back: A Phishing Email Analyzer (Still a Beginner, Still Learning)
A little while ago I wrote about coming back to documenting my work after a long quiet stretch, starting with a small IOC enrichment tool. This is the next entry in that same habit — a phishing email
SOC104 | Malware Detected
Platform: LetsDefend Date Investigated: December 01, 2020 Severity: High Verdict: True Positive ✅ Summary A malware detection fired on an endpoint on December 1, 2020 at 10:23 AM. The file hash came b
SOC137 | Malicious File/Script Download Attempt
Platform: LetsDefend Date Investigated: March 14, 2021 Severity: Medium Verdict: True Positive ✅ File Quarantined: Yes Summary A malicious file was downloaded onto NicolasPRD on Mar 14, 2021 at 07:15
SOC138 | Detected Suspicious Xls File
Platform: LetsDefend Date Investigated: March 13, 2021 Verdict: True Positive ✅ Contained: Yes Summary A suspicious Excel attachment, ORDER SHEET and SPEC.xlsm, landed on endpoint Sofia (172.16.17.56)
SOC145 | Ransomware Detected
Platform: LetsDefend Date Investigated: May 23, 2021 Severity: Critical Verdict: True Positive ✅ Note: This alert was re-investigated Summary EDR/AV flagged ab.exe on host MarkPRD as ransomware at 19:
SOC146 | Phishing Mail Detected: Excel 4.0 Macros (Real Attack)
Platform: LetsDefend Severity: High Date Investigated: June 21, 2026 Verdict: True Positive ✅ Flag: ⭐ This alert was generated from a real phishing attack. Summary This case started as a standard phi
SOC168 | Whoami Command Detected in Request Body
Platform: LetsDefend Date Investigated: February 28, 2022 Verdict: True Positive ✅ Note: This alert was reinvestigated after the first pass Summary The rule fired because the request body contained th
SOC169 | Possible IDOR Attack Detected
Platform: LetsDefend Date Investigated: February 28, 2022 Verdict: True Positive ✅ Escalated: Yes, sent to Tier 2 Summary The alert fired because the same external IP sent several requests to the same
SOC325 | Unauthorized Cloud Region Access Attempt Detected
Platform: LetsDefend Date Investigated: September 24, 2024 Severity: Low Verdict: True Positive ✅ Device Isolated: No Summary An external IP launched a brute force attack against AWS services on Sep 2
SOC336 | Windows OLE Zero-Click RCE Exploitation Detected (CVE-2025-21298)
Platform: LetsDefend Date Investigated: February 04, 2025 Severity: Critical Verdict: True Positive ✅ File Quarantined: No Summary A phishing email carrying a password-protected RTF attachment landed
SOC335 — CVE-2024-49138 Exploitation Detected: Full Walkthrough
Platform: LetsDefendAlert: SOC335 - CVE-2024-49138 Exploitation DetectedEventID: 313Type: Privilege EscalationSeverity: MediumVerdict: True Positive Introduction This is a walkthrough of the SOC335 a
Ship Log #3 | I shipped SoloDesk: A full Freelancer OS built for Pakistani freelancers
Freelancers are among the most active in the world. But most of them are managing clients on WhatsApp, tracking projects in their head, and writing invoices in chat messages. I built SoloDesk to fix t
I built a GitHub analytics dashboard inside a 3D solar system
Seven weeks ago I started Stack Universe as a side project with one question I could not get out of my head. GitHub profiles are boring. What if all that data looked like something alive? Today Phase
Why I'm Building in Public?
Right now I'm working on Stack Universe || a web app that turns your GitHub profile into an interactive 3D solar system. Your repos become planets, commits turn into meteor showers, and an AI narrator