I focus on cybersecurity monitoring, threat detection, and log analysis through hands-on work in a personal SOC home lab.

My work spans the full detection engineering cycle — from generating and analyzing telemetry with Sysmon and Suricata, to building and tuning custom Wazuh detection rules, to validating coverage against the MITRE ATT&CK framework. I investigate real-world attack techniques including credential dumping, fileless malware, reverse shells, and ransomware behavior, documenting each case with the same rigor used in production SOC environments.

I also practice incident triage and evidence analysis, working through case scenarios involving web attack exploitation, brute force campaigns, and RCE vulnerabilities — identifying correct evidence layers and classifying true/false positives.

I maintain a structured lab environment (Wazuh SIEM, Suricata IDS, Sysmon, Kali Linux) and document all findings, custom detection rules, and investigation methodology publicly.

Technologies I work with include Wazuh, Suricata, Sysmon, Linux, and network traffic analysis.

I document my investigations and lab work at vitalijuslab.com and github.com/vitalijus-soc.

Scroll to Top