This repository contains hands-on blue team and SOC analyst projects designed to simulate real-world SOC workflows. Projects focus on:
- Alert triage and investigation
- Phishing analysis
- Log review and incident documentation
- MITRE ATT&CK mapping
- Browser-based threat hunting and OSINT enrichment
All labs are performed using browser-based and open-source tools to demonstrate practical SOC skills.
- Phishing Investigation Lab – Analyze and document phishing emails, identify indicators of compromise, and recommend response actions.
- SOC Alert Triage (Simulated) – Investigate SIEM-generated alerts, validate true/false positives, and escalate confirmed threats.
- Browser-Based Threat Hunting – Proactively investigate suspicious domains, IPs, and URLs using OSINT, enrich IOCs, and assess risk.
Each project includes a README and a detailed case file documenting methodology, findings, and recommended actions.
Saviva Labs — Projects by Jacob