Sydney / Canberra

Marcelo Perlingeiro
Cyber Security Analyst

SOC Analyst Portfolio

Hands on experience investigating real alerts across CrowdStrike, Microsoft Sentinel, Splunk, Wazuh, and LimaCharlie.

CrowdStrike Falcon detections list showing four investigated alerts assigned to Marcelo Perlingeiro
"

I built the SOC Workflow App to keep my own investigations structured — every alert worked the same disciplined way, from first alert to final recommendation.

4
Incidents investigated
6
Lab sessions documented
1
Triage tool built
5
Tools used hands on
SOC Workflow App

A structured way to investigate every alert

Built on the NIST Incident Response framework, turned into a step by step process for working CrowdStrike alerts. Every investigation on this site followed these steps.

1
Confirm the alert and sensor action
2
Pull process lineage
3
Check for lateral spread
4
Map to MITRE ATT&CK
5
Recommend containment or close out
Open the app →
SOC Workflow App showing the shift start checklist for CrowdStrike Falcon investigations
CrowdStrike Investigations

Four alerts investigated end to end

Each one shows what happened, how I confirmed it, and what I recommended.

CASE 001

Registry persistence attempt

A process tried to add a backdoor to a logon script registry key so it would run every time the machine started. Blocked before it could write.

CASE 002

Local password database accessed

A command copied the Windows SAM file, which stores local account password hashes, and User Account Control was switched off in the same session.

CASE 003

Search for stored credentials

A search ran across Group Policy files for an old password field that some networks still use. The search came back empty on this machine.

CASE 004

Attempt to read system memory

A built in Windows tool tried to copy the memory of a process that stores login credentials. Blocked while it was in progress.

View investigations →
Home Lab

Structured attack and defence practice

Building a deep understanding of attacker tactics, and how those attacks actually appear inside SOC analyst tools. Lessons learned from building detection from scratch.

Internet / ISP modem GMKtec mini PC — Proxmox pfSense + Mint Linux jumpbox Firewall, routing, and the management jumpbox TP-Link managed switch Beelink — Proxmox LAN — Wazuh + Splunk VLAN 10 — red team Kali Linux VLAN 20 — blue team targets Metasploitable 3 Ubuntu Metasploitable 3 Windows Windows 10 Ubuntu LTS
SESSION 1

Reconnaissance scan against Metasploitable 3

Ran nmap against the target to learn how reconnaissance shows up in Wazuh, Splunk, and LimaCharlie. Found a gap: no single alert tied the individual service alerts together as one port scan.

SESSION 2

Fixing log collection to catch the scan

The scan was barely visible in Wazuh because it was not reading the right log files. Fixed file permissions, expanded log collection, and wrote a custom rule that correctly fired on the scan.

SESSION 3

Reading Splunk properly to investigate an attacker

Logs were arriving unparsed with no searchable fields. Fixed the source type mapping, then ran a full investigation from zero and found one IP that had scanned every web application on the box.

SESSION 4

Comparing how three tools see the same scan

Watched the same nmap scan appear three different ways: a high level alert in Wazuh, raw log detail in Splunk, and full process level behaviour in LimaCharlie, including a root process with no alert raised.

SESSION 5

Why the SIEM missed it and the EDR didn't

Used a documented backdoor exploit to get a working shell. Wazuh missed the entire attack because it never touched a monitored log file. LimaCharlie caught the full process chain at the kernel level.

SESSION 6

Writing a detection rule to close that gap

Built a LimaCharlie rule from scratch to catch the exact pattern Session 5 missed. Tested it against fake data first, then re ran the real exploit twice to confirm it fired against the actual attack.

View full lab journal →
Background

Skills & certifications

Detection & Response

  • CrowdStrike Falcon
  • Microsoft Sentinel (KQL)
  • Splunk SIEM
  • Wazuh / LimaCharlie
  • Tenable Nessus

Frameworks

  • NIST Incident Response
  • MITRE ATT&CK
  • Essential Eight
  • ISO 27001 fundamentals

Certifications

CompTIA Security+Jun 2026
CyberXcel Applied Security Program2026
Master of Business (Marketing), UTS2006

Infrastructure & Tools

  • Proxmox / pfSense
  • VLAN segmentation
  • Kali Linux
  • ANY.RUN / CyberChef

Get in touch

All investigations were conducted in a CrowdStrike training environment as part of the CyberXcel Applied Security Program. Lab machines are personal lab assets.