Jason Hill, 8-bit style

visitor@thefish.nz:~$ home

Jason Hill

CYBER SECURITY · OSINT · DIGITAL INVESTIGATIONS

Security operations by trade. OSINT by curiosity, persistence, and an inability to leave an interesting clue alone.

// latest posts

Recent Posts

Windows Event Logs for SOC Analysts: What an Event ID Actually Proves

Read post →

Threat Hunting for SOC Analysts: Turning a Suspicion Into a Searchable Hypothesis

Read post →

SPF, DKIM and DMARC: What They Actually Prove (and What They Don't)

Read post →

Ransomware Before the Ransomware: What the SOC Should See Before Encryption Starts

Read post →

PowerShell Is Not the Alert: Investigating Living-off-the-Land Activity

Read post →

The IP Isn't the Attacker: A SOC Analyst's Guide to NAT, VPNs and Proxies

Read post →

Identity Attacks for SOC Analysts: Sessions, Tokens, MFA and Account Compromise

Read post →

How to Think Like a SOC Analyst in an Interview

Read post →

From Header to Host: Investigating Phishing in the SOC

Read post →

See all posts →

$ connect --linkedin

Get in touch

Questions about OSINT, security operations, or an interesting rabbit hole to share? LinkedIn is the best place to reach me.

Other places: @OscarThePhish GitHub