Currently: Monitoring Enterprise Environments

Sam
Fiera

SOC Analyst & Cyber Security Specialist

Building a career in cybersecurity — defending enterprise environments through threat detection, incident response, and continuous security monitoring. Outside the SOC: soccer, football, gaming, and music production.

View Case Studies → Get in Touch
4Years in Security (including School and internships)
9Certifications
BachelorsHonours Degree in Cybersecurity
Full TimeSOC Analyst

The Lab

Case Studies

Real-world investigations and engineering projects. Details anonymised to protect client confidentiality.

Case // 001

SecureCTF — Gamified Cybersecurity Learning Platform

Problem

New analysts and students entering cybersecurity lack engaging, hands-on environments to learn core concepts and terminology without expensive lab infrastructure.

Action

Designed and built a short-form gamified CTF platform to teach fundamental cybersecurity functions and terminology through interactive challenge-based learning.

Result

A fully functional platform hosted on GitHub, providing a free, accessible entry point for learners to build foundational security knowledge in a structured game format. Submitted as the final capstone project for a BSc (Hons) Cyber Security at The Open University — graduating with a 2:1.

Case // 002

YOOLBOT — Personal AI Security Companion & Home Server

Problem

Needed a 24/7 AI-accessible assistant capable of running automated security tasks and background jobs without exposing personal data or risking a compromised host environment.

Action

Wiped a laptop to a clean state and hardened it as a dedicated home server with secured ports and a locked-down security posture. Deployed OpenClaw with WSL2, integrated Google Gemini Flash, and configured a Telegram bot for 24/7 mobile access via a VPS relay.

Stack
OpenClawWSL2Gemini FlashTelegram Bot APICronVPS Relay
Result

A fully operational AI companion running 24/7 — reachable via Telegram from anywhere, capable of autonomous background tasks, and hosted on isolated hardware with no personal data exposure.

Case // 003

AUTOR — Contain Host

InsightConnect Automation · Rapid7 + Cortex XDR Integration

Problem

Containing a potentially compromised endpoint required pivoting across multiple consoles, adding friction and time during an active incident where speed matters most.

Action

Built a Teams-triggered host isolation workflow in Rapid7 InsightConnect. An analyst types contain-host <asset> in the designated channel. The workflow looks up the host in Cortex XDR, prompts the analyst with a human-in-the-loop confirmation gate, isolates on approval, then automatically pulls forensic artifacts — running processes, network connections, and the IDR timeline — and posts a snapshot card back to the thread. An audit log entry is written to InsightIDR before the flow exits. Declined requests exit cleanly with an “Operation Aborted” post.

Stack
InsightConnectCortex XDRInsightIDRMicrosoft Teams
Result

Reduces time-to-containment from a multi-step manual process across two consoles to a single Teams message. Forensic context is captured automatically at isolation time, preserving evidence without analyst intervention.


Terminal

Security Write-Ups

Short-form technical notes from the trenches. Updated periodically.

sam@soc ~ /feed
2026-09-10 // 09:00:00 UTCThreat Hunt

ShieldCrash: Hunting Symlink-Based Credential Hive Access (CVE-2026-69414)

Microsoft Defender’s scanning engine runs with SYSTEM privilege, which makes it a useful proxy for an attacker who wants to read something they cannot touch directly. ShieldCrash abuses exactly that: a symlink planted under a system config path redirects MsMpEng.exe into opening one of the Windows credential hives — SAM, SECURITY or SYSTEM — so Defender harvests the credential material on the attacker’s behalf. I hunted it in Cortex XDR with an XQL query keying on FILE_OPEN and FILE_LINK_READ events where the actor process is MsMpEng.exe and the resolved path terminates at one of the three hives. An unfiltered baseline confirmed the query matched real telemetry; the full logic then returned zero hits across a 30-day lookback. With no out-of-the-box detection confirmed to cover the technique, the hunt was promoted to a standing BIOC rule.


2026-02-15 // 09:00:00 UTCDetection Rule

DNS-Based ClickFix: Detection Rule for nslookup Payload Staging

Microsoft disclosed a new ClickFix variant that abuses nslookup to retrieve second-stage payloads over DNS rather than HTTP — making it harder to catch with traditional web-request detections. The full attack command runs through cmd.exe, performs a DNS lookup against a hardcoded external resolver, then pipes the output through findstr "^Name:" to extract and execute the payload embedded in the DNS response. I built a detection rule in Cortex XDR using XQL to surface this behaviour, keying on process events where the command line contains nslookup combined with findstr — a combination that has no legitimate use case in the environment and fires with high confidence and minimal false positive risk.


2026-01-01 // 00:00:01 UTCTest

Terminal Test Entry

Initial entry confirming the terminal feed is rendering correctly. Further write-ups will follow as investigations and detection work is documented.


sam@soc:~$ Add new entry

Credentials

Certifications & Education

Validated expertise across vendor and academic pathways.

Verified

Certified in Cybersecurity (CC)

ISC2

View on Credly ↗

Verified

CCNA — Introduction to Networks

Cisco

View on Credly ↗

Verified

BSc (Hons) Cyber Security

The Open University

Graduated — 2:1 Honours

Verified

CCNA — Switching, Routing & Wireless Essentials

Cisco

View on Credly ↗

Verified

InsightIDR Specialist

Rapid7

Verify Certificate ↗

Verified

InsightVM Certified Administrator

Rapid7

Verify Certificate ↗

Verified

InsightConnect Specialist

Rapid7

Verify Certificate ↗

Verified

CompTIA Security+

CompTIA — SY0-701

Verify Certificate ↗

To verify, visit the link and enter the code: c993b2cbcd2440fcb12752909c8406c6

Verified

Cortex XDR: Features

Palo Alto Networks

Certificate of Completion — September 2026

Training hours 12:25 · ID C596136

Verified

Cortex XQL

Palo Alto Networks

Certificate of Completion — September 2026

Training hours 04:25 · ID C596121

Active subscriber — ongoing hands-on lab practice across offensive and defensive tracks.

View Profile ↗

Technical Arsenal

Tools & Capabilities

Core competencies across detection engineering, response operations, and identity security.

🔍

Threat Detection

Authoring detection rules and hunting queries across enterprise SIEM and XDR platforms to surface anomalies and TTPs aligned to MITRE ATT&CK.

KQLLEQLXQLMITRE ATT&CKSIEM Tuning
🛡️

Incident Response

End-to-end IR from initial triage through containment, eradication, and post-incident review. Proficient in enterprise EDR and XDR platforms.

Cortex XDRMicrosoft DefenderPlaybook DesignForensics
🔐

Identity Management

Securing identities at scale — managing Conditional Access, Privileged Identity Management, and investigating identity-based attack chains.

Entra IDPIMZero TrustMFA
📊

Security Monitoring

Building and maintaining dashboards, alert rules, and correlation logic to maintain situational awareness across multi-cloud environments.

SentinelSplunkLog AnalysisAlert Tuning
⚙️

Automation & Scripting

Accelerating SOC workflows through SOAR playbooks, custom Python utilities, and PowerShell scripts for rapid triage and enrichment.

PythonPowerShellSOARAPI Integration
☁️

Cloud Security

Monitoring and securing cloud workloads, reviewing IAM postures, and investigating cloud-native threats across Azure environments.

AzureDefender for CloudIAMCSPM

Contact

Get in Touch

Open to incident response consultancy, detection engineering projects, and cybersecurity roles. Reach out via any channel below.

PGP Public Key

For sensitive communications, encrypt messages using the public key below. Verify the fingerprint independently before sending.

Fingerprint: 5909 CDA8 CB9F 1E5C 870E  5876 9CBF 24F9 03D1 8D0C

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGnSa8wBEADNZy1vfw3R7vfncn+K7Ey0S5ASANDzAAEESWjyOBnQ9vh3RM5q
nyXcKt5bHap1ag5E7K+jISSreu5GMFt/pl5ZZKnjqvsnUVYDij2M9yY2WkcXz45s
+gZVieFfZzjEKy9fSaCjqDB5s8dm2VGOPStTj1xjkAVZfLz9zxG3qvittuuiz2Ju
jMIciSZZRpV4fqoKMcRK2QnlV5hg+W5bJm6PbEALHf3T1Gsi4FvmYd9reyZhhLvI
BU7GjXQniDQxZvZQA8nZZ2BdXiwW6nwzNu6fd0+C+KXNrX5z4DtpBQvaNJuo5v6P
GjRRi6hAPZ719yE4xdl1xvDWa0wWhKJOe6L0rzRt/U3O2yOG6cxFG+oFDji4C4Zr
HDWLk9zwA5kFLGV2RarmqvHd+qOGIYIPyzlU8R/D3yFWGkVgvsPZkNnF04Q18ls5
Wrx5z84yQMhDKXOm9P+36yG4ry7ZDZ3lyLSJ7k9eijTLaoMLnWYWCzXxQUO+VVg/
9uC/c+uQV8G+KW0KiuOvc4kHVAR+uqbszOdMzlPtrR3I99NxpJMmcXbB/R1VnCHT
pHYmBy7Vkha3ojj0uqjBiFe+A2juDHcnqHUCYy47t7Os8lDrKQtYtXaH2E7MfrSp
bE8wO2xs6HK2Y4v5mtChF9RD5doNzbMcKtSxneRWYRQrar26aKYswX2cbwARAQAB
tCdTYW0gRmllcmEgKHlvb2wpIDxzYW1maWVyYTQ0QGdtYWlsLmNvbT6JAnMEEwEI
AF0WIQRZCc2oy58eXIcOWHacvyT5A9GNDAUCadJrzBsUgAAAAAAEAA5tYW51Miwy
LjUrMS4xMiwyLDECGwMFCQlmAYAFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AA
CgkQnL8k+QPRjQy/rA//WfpZvxFUYqX8PVaEHXxleiJjSizMwURxQ/Ft9w6sOcfl
RI9pC2R4PuldFMvOm533xf4Ix7kqGFebrr+rUcV5hTbU30qLijLC0c/BfcGaY072
ccFqWnAYuydqCqZq+VKnQoJZrhkxm9AW1CT2yrrDJiUz60hZdLGdHjJp782f1G+2
X8kMoudiDYM5ZW9c531pPzgjAlG+wCbRuK7ZZ2iblTp6H2yxQWOGYM01aY0LzsHt
yY38Yix26UrD5UgP2ScCSAnwJK1tCcvnKzBxgKS9xNdYEs68MrKkND6w8rTH4q72
Tw15VL+ZKxnsAyM0+HH5M203DbOXoqH72z+sGC4WZtEpGwfLhbVdPbmQ8Ro/Vjii
Zm36oPa6fGR+pU1JZgp3XwN8vJkXRgZhy8rzI9tQUeu9uWTHehjKwEpY6xvGEMW0
kk510H04x7LOnAMAuUgo0xYdryBY+ShSGe4/+7RO49OR8LEu3NbTxynO2Q8Qna17
Moq1C40z9vOF88RN3gE4GHc10jdEgyXAwsZQxWXWYGpJp1MJ8n3wfTtlvz2OJtbS
WY2JXvizOJyHMbrx3nkxgsbk1TTD/OjTIknvQGzotGSFtMpH4rQ3ZvsiyrCW3YCw
dSEYn21dK4YTk2i9yxJHXHBRBOftTGU6zp5jXIgZhVjgMyWRKeRjvnj5O30Xy/25
Ag0EadJrzAEQALz8FtNwM64A7eKaTZWY+LaFvBH8Gca6+fwyDFSJq0Io+lnge6Nn
Ggpl3CgFYagYqvLu59qFp7WIxe+tGNwJM82xIKXkysv7+Qm57O2unUeyn3OozqH/
Y+6CV1XuSJyLJuoRkc2DPpe33aPbZRkpta5s5J2Tr6U6wXaa+bLnS5TKCqwl3W+C
Xolq7sbzFgvbI+dGlUYyM1myV+MC5pyiq5hNg0UQxGtXcHcoIuOWJv8A2HoaDQdn
85XEGeSERKjhqcqiPSEGlhprCpkthfcj+GuUvJ0HD1HXKV2LK+8zRpctr6v23hXB
1G8ZEY5potHHZAfi2z80IfeOm46f2vqrXoKLgphlHtu22LD2lc519KNyYfk7pBpv
0dSaqxckAExc7jnBjEm3zUym2LdNgFjRcO9z1+UbKocj8JdxaT/PU9VynF3Fmpc0
mdAszKYlyxkbbLp4c88kNdr8yDPYbHtVaMDseuxBmlIU8VIGMqq/5nfw9I+MjKW+
fLsBkHhM5ZNbmOF1M6DAk6JHD7sxN+3Fl0skff9j+rvNenGUL13XXiGIcRw1PYqx
hnNGZkxiR91joUx0zC58RxRsernQO4yuFt2BaSGR/GuAtWQtO8Q2uWjuAgWMXiT2
oT9JewbVmSADDyes406Drh2NDvtLZmxb0+lDz6aXKnIA54pasw3BnG2NABEBAAGJ
AlgEGAEIAEIWIQRZCc2oy58eXIcOWHacvyT5A9GNDAUCadJrzBsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDECGwwFCQlmAYAACgkQnL8k+QPRjQyeoQ//aPYhcqid
+O+g3vp/K3FxBVufaHM1Ew7JaYwF0Kp9CFG8105+Nf1x06LB1yHCwx8GLXo46QSk
hgF4iz3f9BjrlvujAK4W/axJdIJyFQMfIWfs1X4geYfkpuK5lhYO+R0kkBxOnEyN
gBxFpNfcb3C6oxr1zEv6RdtrLVR44XUepvGiVEgJFPMVlwZVAvsfhlibPCm/jXBP
VFJ9vcKsD+gvnAROs1+D3aAoJ0hrjsGwUm430iBSxgiYdW4E2aLZqSgtb3Oa46nf
Aj4fv4hTXUv8Uw4WT97refqwegXGen5nkI9qlHwRH82F7NESeRtN7/wSN6fJE4m/
k5Czj3CNbtIyKKdhvlO20Nzb9w0bJtnVKAaxabkaRxPX9sdA2Eh1WIfvPqxQ/Djb
qfW+fU2/UqUAOjG6sphgYTeBbk4wNDwbxfeQ3ISkCR9Iuvxwl3raoKpsFGd68n0m
TDxECSt4GgH3MfvuwYkEUkunLIq417K1lA3lmO27/xtNXlu+GyDliliFSprdRNvZ
5qvMNIrn99Kv+oUEVUNx7RrEnAXtdXEJiaWsSkLjOpqqZNzP02s7Qx5nt7apaHns
mGStLWZPYXDLGGhDCyR2XDqVSjumF0L8eW5YyWH2jZw1+nwCSC2lUKzkfYLBl6oF
rMj0n7FqpA1wowMVYaqrP02Ew8ZoznHh5iU=
=4wlV
-----END PGP PUBLIC KEY BLOCK-----