Cybersecurity Portfolio

Hi, I'm Ho Quoc Thai

Network Security Student | SOC Analyst in Training | CTF Player

I am a cybersecurity learner focusing on SOC analysis, log investigation, threat detection, and hands-on security labs.

SOC Alert triage
SIEM Wazuh labs
CTF Write-ups

About

Focused on practical security investigation

I am a network security student currently training to become a SOC Analyst. My learning path focuses on analyzing security events, investigating logs, understanding attacker techniques, and building practical detection skills through labs, CTFs, and real-world security scenarios.

I enjoy learning by doing: building labs, solving CTF challenges, writing reports, documenting findings, and improving my ability to investigate security incidents.

Threat Detection Log Investigation Digital Forensics Security Labs

Skills

Technical skill areas

Organized around SOC work, operating system fundamentals, security practice, and tools.

01

SOC & Blue Team

  • Log analysis
  • Alert triage
  • Incident investigation
  • Wazuh SIEM
  • MITRE ATT&CK
  • IOC analysis
  • Detection logic
02

Operating Systems

  • Windows logs
  • Linux logs
  • PowerShell basics
  • Bash basics
03

Security Practice

  • OSINT
  • Digital forensics
  • Web security testing
  • Basic malware analysis
  • CTF problem solving
04

Tools

  • Wazuh
  • Burp Suite
  • Nmap
  • Wireshark
  • Sysmon
  • Linux CLI
  • GitHub

Projects

Hands-on cybersecurity projects

Practical labs and documentation focused on investigation, detection, and evidence-based analysis.

Blue Team Lab

SOC Alert Investigation Lab

A hands-on lab focused on analyzing security alerts, reviewing logs, identifying suspicious behavior, and classifying alerts as false positive or true positive.

SOC Wazuh Log Analysis MITRE ATT&CK
Windows Security

Windows Log Analysis with Sysmon

A practical project for collecting and analyzing Windows event logs using Sysmon to detect suspicious PowerShell execution, process creation, and file activity.

Windows Security Sysmon PowerShell Threat Detection
Documentation

CTF Write-ups Collection

A collection of CTF write-ups covering web exploitation, forensics, OSINT, reversing basics, and security problem-solving methodology.

CTF Web Security Forensics OSINT
Malware Basics

Malware Behavior Analysis Notes

Basic malware analysis notes documenting suspicious behaviors such as persistence, registry modification, command execution, and network indicators.

Malware Analysis IOC Registry Sandbox

CTF Write-ups

Challenge notes and solving methodology

Blog-style cards for documenting the problem, evidence, exploitation path, and lessons learned.

Web Exploitation

File Upload Vulnerability Lab

Difficulty: Easy

Analyzing weak upload validation, identifying execution paths, and documenting controlled exploitation steps.

Read more
Digital Forensics

Windows Registry Investigation

Difficulty: Medium

Reviewing registry artifacts, deleted traces, persistence indicators, and evidence extraction workflow.

Read more
OSINT

Public Source Investigation

Difficulty: Easy

Using public metadata, visible clues, and structured search methods without crossing privacy boundaries.

Read more
Reverse Engineering

Basic Binary Analysis

Difficulty: Medium

Reading program behavior, identifying strings, checking file formats, and building a repeatable analysis process.

Read more

Security Notes

Short technical references

Concise notes for concepts, commands, detection logic, and investigation workflows.

01

PowerShell suspicious behavior

02

WMI Event Subscription

03

PsExec-like remote execution

04

Registry persistence

05

Wazuh decoder and rule writing

06

MITRE ATT&CK mapping

07

IOC investigation workflow

Learning Roadmap

Cybersecurity learning path

A practical path toward SOC analysis, detection engineering fundamentals, and stronger portfolio documentation.

01

Networking fundamentals

02

Linux and Windows fundamentals

03

Log analysis and SIEM basics

04

SOC alert triage

05

MITRE ATT&CK and threat detection

06

Digital forensics and malware basics

07

CTF practice and project documentation

08

Build a strong SOC Analyst portfolio

Contact

Connect and collaborate

For projects, write-ups, labs, and cybersecurity learning documentation.

Always learning. Always investigating. Always improving.