DFIR • Red Team Operations • Cyberspace Analysis • Security Engineering
I am an emerging Cyber Beast building toward a career at the intersection of Digital Forensics & Incident Response (DFIR), Red Team Operations, and Cyberspace Analysis.
My objective is not to stop at SOC Tier 1. A SOC role is a valuable operational foundation for me — a place to sharpen detection, investigation, telemetry, and incident-response skills while progressing toward deeper offensive and forensic work.
I am interested in understanding the complete attack lifecycle:
Reconnaissance → Initial Access → Execution → Persistence → Privilege Escalation → Lateral Movement → Collection → Exfiltration → Detection → Investigation → Forensic Reconstruction
The goal is simple:
Understand how systems are attacked, how attacks are detected, how evidence survives, and how the entire operation can be reconstructed.
| Domain | Focus |
|---|---|
| 🔎 DFIR | Disk, memory, endpoint and network investigation; IOC extraction; incident reconstruction |
| 🔴 Red Team Operations | Reconnaissance, vulnerability assessment, web application testing, C2 concepts and adversary simulation |
| 🌐 Cyberspace Analysis | OSINT, attack-surface discovery, Shodan/Censys-driven reconnaissance and infrastructure analysis |
| 🧬 Reverse Engineering | Malware triage, behavioral analysis, static/dynamic analysis and Windows/Linux internals |
| 🛡️ Threat Hunting | PCAP analysis, telemetry, anomaly detection and detection engineering |
| 🐞 Bug Hunting | Web application security, OWASP Top 10, secure code assessment, recon and smart fuzzing |
| ⚙️ Security Automation | Python, PowerShell and Bash for repeatable security workflows |
My learning environment is built around isolated virtualized systems and deliberately controlled experimentation.
Primary environment
- VMware Workstation Pro
- WSL Ubuntu
- Kali Linux
- REMnux
- Security Onion
- Windows virtual machines
- Isolated malware-analysis environments
- Network-monitoring and chaos-testing environments
The lab is where theory becomes evidence:
┌─────────────────────────────────────────────────────────┐
│ CYBER LAB │
├─────────────────┬─────────────────┬─────────────────────┤
│ OFFENSE │ DEFENSE │ FORENSICS │
│ │ │ │
│ Kali │ Security Onion │ Volatility │
│ Burp Suite │ Wireshark │ FTK Imager │
│ Nmap │ Suricata │ Autopsy │
│ Metasploit │ Elastic Stack │ strace │
│ C2 Frameworks │ Log Analysis │ IOC Reconstruction │
└─────────────────┴─────────────────┴─────────────────────┘
The long-term project I want to build is an AI-integrated Ultimate Pentest Tool that unifies three perspectives of cybersecurity:
- Intelligent reconnaissance
- Attack-surface mapping
- Automated enumeration
- Smart fuzzing
- Vulnerability discovery
- Controlled exploitation workflows
- Detection engineering
- Telemetry collection
- Threat hunting
- IOC correlation
- Alert generation
- Defensive validation
- Evidence collection
- Memory analysis
- Artifact extraction
- Timeline reconstruction
- IOC generation
- Incident investigation
The ambition is to create a platform where offensive testing produces defensive intelligence and forensic evidence rather than treating these disciplines as isolated worlds.
Burp Suite Nmap Metasploit Nessus Cobalt Strike Sliver Mythic Empire BloodHound evilginx2
Shodan Censys OSINT Attack-Surface Discovery
Volatility Autopsy FTK Imager ClamAV strace IOC Analysis
Wireshark Suricata Elastic Stack ELK Stack
Python PowerShell Bash
Linux Windows WSL RHEL
Hands-on malware analysis across Windows and Linux environments using ClamAV, Volatility and strace, with IOC documentation and remediation guidance.
Configured ELK Stack for centralized logging and developed automation workflows for near-real-time security-log analysis and anomaly detection.
Developed a blockchain-based certificate generation and validation system using Ethereum, smart contracts and web3.js.
A growing collection of scripts, labs and experiments focused on security automation, system analysis, offensive testing, defensive telemetry and forensic investigation.
- Red Hat Certified System Administrator (RHCSA EX200V9) — Feb 2024
- Google Cybersecurity Professional Certificate — Jun 2024
- TryHackMe Advent of Cyber 2024 — Dec 2024
- TryHackMe: 28 badges and 379 rooms completed at the time recorded in my resume
- Bug Hunting: Ongoing freelance web application security and secure-code assessment work
SOC Operations
│
├── Detection & Telemetry
│
├── Threat Hunting
│
├── Incident Response
│
▼
DFIR
│
├── Memory Forensics
├── Malware Analysis
├── Network Forensics
└── Endpoint Investigation
│
└──────────────┐
▼
Red Team Operations
│
Cyberspace Analysis
│
▼
Security Engineering
I want to understand the whole ecosystem, not just one layer of it.
- GitHub: https://github.com/2171001
- LinkedIn: https://www.linkedin.com/in/abel-benedict-364a911b9/
- TryHackMe: https://tryhackme.com/p/anon.techy111
- picoCTF: https://play.picoctf.org/users/abelbenedict
Explore the repositories.
The real work lives in the code, labs, experiments and evidence.