William · SOC Analyst (Tier 1)

21.3K posts

William · SOC Analyst (Tier 1) banner
William · SOC Analyst (Tier 1)

William · SOC Analyst (Tier 1)

@WilliamInCyber

SOC Analyst (Tier 1) | Splunk · SIEM · MITRE ATT&CK | 28 hands-on labs | SA-based, UK/Gulf timezone overlap | Open to remote roles

Johannesburg, South Africa انضم Mart 2020
973 يتبع913 المتابعون
تغريدة مثبتة
William · SOC Analyst (Tier 1)
William · SOC Analyst (Tier 1)@WilliamInCyber·
🛡️ SOC Analyst (Tier 1) | Building in Public What 28 days of real blue-team work looks like: 🔍 Splunk · SIEM · Log Analysis 🧠 MITRE ATT&CK · Threat Detection 💻 Kali · Ubuntu · Windows lab 📜 ISC2 Certified in Cybersecurity
William · SOC Analyst (Tier 1) tweet media
English
8
14
196
4.7K
William · SOC Analyst (Tier 1)
The "silently fail, no console logs" comment in that JS is the tell built to dodge the analyst doing exactly this kind of triage. Device-code phishing is nasty because the victim generates a real token; the only signal is an auth from a context that shouldn't have one. IOCs noted
Anurag@Malwarehunterr

Fake Microsoft Teams device code phishing page Interestingly, the same site was used about a year ago to host Microsoft/Outlook phishing content. URLs: readfile[.]online login.vvorkpage[.]online Old scan: urlscan.io/result/0195f40… #phishing #devicecodephishing #microsoft365 #teams @500mk500 @urlscanio

English
0
0
3
41
William · SOC Analyst (Tier 1)
"Getting good takes time" is the part nobody screenshots. I'm months into building SOC labs before applying for a single role brute-force hunts, PowerShell detection, mentoring someone through the same path. No shortcut showed up. The compounding is quiet but it's real.
Emmanuel AO • DevOps & Tech@emmanuelao_

The internet made people believe you can learn tech in 12 months, open an Upwork account, and start earning thousands immediately. Reality hits differently. Getting good takes time. Finding clients takes time. Building trust takes time.

English
0
0
1
19
William · SOC Analyst (Tier 1)
Agreed, but I'd add one nuance: the GitHub only tells the story if the repos show decisions not just code. My SOC labs read like incident reports methodology, IOCs, MITRE mapping. That's the part a recruiter can't fake having done. Certs prove you studied; repos prove you shipped
Emmanuel AO • DevOps & Tech@emmanuelao_

Nobody hires you because you collected certificates. They hire you because you can build, debug, and ship. Your GitHub tells that story better than Coursera ever will.

English
0
0
2
32
Manly Mentor
Manly Mentor@manly_mentor·
Protect this queen at all costs 👑 ‼️
English
26
659
2.3K
80.5K
William · SOC Analyst (Tier 1)
MAC address table. The switch reads the source MAC of each frame, records its port, and forwards future traffic there. Unknown destination = flood all ports once, learn the reply, then unicast. That same table is where a SOC spots MAC flooding attacks.
Cyber_Racheal@CyberRacheal

You plug an Ethernet cable into a switch port, The link light flashes bright green, Data transfers at maximum speed. How does the switch know where to send your data?🤔

English
1
1
9
262
William · SOC Analyst (Tier 1)
@CyberSamuraiDev Mr. Robot was right. Every breach I've read this week came down to a human granting access, not a CVE firing. The vishing call into Charter is the cleanest example no malware, just a convincing voice. Hardest layer to patch is the one that answers the phone.
English
0
0
1
27
Julian Derry
Julian Derry@CyberSamuraiDev·
@WilliamInCyber In the words of Elliot Alderson, “People always make the best exploits.”
English
1
0
2
141
DALU🤍
DALU🤍@iam_dalucynthia·
@WilliamInCyber 😹😹😹😹 As funny as this sounds... it's highly undisputable 😹 This is a world of constant learning and practices, if you snooze you loose😹
English
1
0
2
11
William · SOC Analyst (Tier 1)
@somadinaaaa Yeah, can't argue with securing the pipe. I just file the VPN under "necessary, not sufficient" it does nothing once an attacker has valid creds, which is where most of my lab incidents start. Right tool, just not the last line of defense.
English
1
0
0
15
SOMA
SOMA@somadinaaaa·
@WilliamInCyber so does every part of the internet. but we shall do the best we can and play with the cards we're given. we're all vulnerable to an extent but a vpn makes sure the tunnelling is secure.
English
1
0
1
14
William · SOC Analyst (Tier 1) أُعيد تغريده
William · SOC Analyst (Tier 1)
Prompt injection is ranked number 1 on the OWASP Top 10 for LLM Applications. Most SOC teams have zero detection for it. Today I built one from scratch. Here is how Day 2 of my SOC detection lab went 🧵
William · SOC Analyst (Tier 1) tweet mediaWilliam · SOC Analyst (Tier 1) tweet mediaWilliam · SOC Analyst (Tier 1) tweet mediaWilliam · SOC Analyst (Tier 1) tweet media
English
1
5
9
201
William · SOC Analyst (Tier 1)
That "create hidden admin" payload is the detection problem I filed a SigmaHQ gap on (#6057) rogue admin creation has evasion paths that slip past surface rules. Plus a hidden web shell for persistence. The account creation IS the IOC worth hunting, not just the script.
The Hacker News@TheHackersNews

🛑 Popular #WordPress plugin scripts were tampered with to plant hidden backdoors. The attack hit #JavaScript used by PushEngage, OptinMonster, and TrustPulse. If a logged-in admin loaded the script, attackers could create a rogue admin account and install a hidden web shell. Over 1.2M sites run the three plugins. Read the full article: thehackernews.com/2026/06/popula…

English
0
0
1
25
DALU🤍
DALU🤍@iam_dalucynthia·
@WilliamInCyber I keep telling people...the journey didn't promise to be easy, if you desire to be at the peak, you must give up what everyone else isn't willing to give up and that's comfort. Discipline will become your second name.
English
1
0
1
13
William · SOC Analyst (Tier 1)
"No second click required" is the scary part. The exfil rides Copilot's own trust in a microsoft[.]com link exactly the failure I saw in prompt-injection testing: the agent treats trusted-origin input as a trusted instruction. CVE patched, but detection for this class is thin.
International Cyber Digest@IntCyberDigest

‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required. Microsoft has patched it as CVE-2026-42824, rated critical.

English
0
0
0
52