open to SOC L1 opportunities // Cybersecurity Student · Blue Team
y2z3@sec — zsh — 80×24
$
Yazan Abu Mahmoud
y2z3// cybersecurity handle
$
Cybersecurity Student | SOC Analyst | DFIR
$
Blue Team · SOC Operations · Digital Forensics · Incident Response
$
TryHackMe — Rank #65,308 (Top 3%) · 115 rooms · 25 badges
Top 3%
TryHackMe global rank
115
Rooms completed
25
TryHackMe badges
#2
AAUCTFv1 CTF
5
Certifications earned
certifications

Verified credentials

Every badge below is independently verifiable — click through to the issuer's own verification page.

CCDL1 badge
CyberDefenders · July 2026
CCDL1
Certified CyberDefender Level 1 — blue team fundamentals across log, network, and endpoint analysis.
verify on credly ↗
CompTIA Security+ badge
CompTIA · Oct 2025
Security+ (SY0-701)
Industry-standard baseline cert covering security architecture, operations, and risk management. Valid through Oct 2028.
verify on credly ↗
HV
Hackviser · Core Track
HV-CORE
Hackviser Core certification — hands-on offensive/defensive exercises across realistic attack scenarios.
verify ID: HV-CORE-HKL7HJZE ↗
TryHackMe badge
TryHackMe · Oct 2025
Pre Security Path
Foundational path covering networking, web, and Linux/Windows fundamentals — 7h 38m of hands-on rooms.
verify on tryhackme ↗
TryHackMe badge
TryHackMe · May 2026
SOC Level 1 Path
65h 29m path covering SIEM triage, threat intel, log/network/endpoint forensics, and phishing analysis.
verify on tryhackme ↗
achievements

Rankings & competitions

Top 3%
TryHackMe — Global Ranking
Ranked in the top 3% of all TryHackMe users worldwide across rooms, paths, and CTFs.
view profile ↗
2nd Place
AAUCTFv1 — Capture The Flag
Placed 2nd overall in the AAU CTF v1 competition against university teams.
view credential ↗
2 Paths
TryHackMe Path Completions
Pre Security & SOC Level 1 — 73+ hours of structured, hands-on blue-team training.
view profile ↗
projects

Hands-on labs

Self-built detection & forensics labs, documented and version-controlled on GitHub.

CySYzn / suricata-wazuh-ids-lab
Suricata + Wazuh IDS Lab
Network-based intrusion detection lab using Suricata + Wazuh, validated against a live vsftpd 2.3.4 backdoor exploit on Metasploitable2.
SuricataWazuhMetasploitable2
view repo ↗
CySYzn / wazuh-rdp-bruteforce-detection
Wazuh RDP Bruteforce Detection
Host-based intrusion detection lab using Wazuh + Sysmon, validated against a live RDP brute-force attack (Hydra) and unauthorized remote access on a Windows 10 endpoint.
WazuhSysmonHydra
view repo ↗
CySYzn / phishing-email-forensics-lab
Phishing Email Forensics Lab
Hands-on forensic analysis of a synthetic phishing email — header/routing inspection, SPF/DKIM/DMARC verification against a real domain's DNS records, and malicious-PDF triage using pdfid and pdf-parser.
SPF/DKIM/DMARCpdfidDFIR
view repo ↗
writeups

Lab writeups

Full methodology, real commands, real screenshots — every question answered and explained, not just the flag.

CYBERDEFENDERS · RETIRED RedLine Lab Endpoint Forensics · Memory Analysis · Easy $ vol -f MemoryDump.mem windows.malfind tools: Volatility 3 · Strings
CyberDefenders · Endpoint Forensics · Easy
RedLine Lab
Volatility memory forensics — process hollowing, a hidden Outline VPN tunnel bypassing NIDS, and full C2 attribution from a single memory image.
CYBERDEFENDERS · T1110.003 T1110-003 Threat Hunting · Password Spraying · Easy index="t1110-003" "event.code"=4625 tools: Splunk · ELK
CyberDefenders · Threat Hunting · Easy
T1110-003
Splunk threat hunting for an RDP password-spray attack — timing the bruteforce window, identifying compromised accounts, and mapping detection to MITRE T1110.003.
CYBERDEFENDERS · RETIRED Sysinternals Lab Endpoint Forensics · Trojanized Software · Medium $ AmcacheParser.exe -f Amcache.hve --csv . tools: Autopsy · AmcacheParser · VirusTotal
CyberDefenders · Endpoint Forensics · Medium
Sysinternals Lab
A trojanized SysInternals download traced through Amcache/AppCompatCache artifacts to a Rozena downloader, its C2 domain, and a fake Windows service used for persistence.
seed phrase ••• ••• ••• ••• CYBERDEFENDERS · RETIRED GrabThePhisher Threat Intel · Crypto Wallet Phishing · Easy $ cat metamask.php tool: text editor · exfil: telegram bot
CyberDefenders · Threat Intel · Easy
GrabThePhisher Lab
Source-level analysis of a live crypto wallet phishing kit — mapping its geolocation lookup, harvested seed phrases, and Telegram exfiltration channel back to the developer.
CYBERDEFENDERS · RETIRED PhishStrike Threat Intel · Email Header Analysis · Medium spf=softfail dkim=fail C2: gh9st.mywire.org tools: URLhaus · VirusTotal · MalwareBazaar · VMRay
CyberDefenders · Threat Intel · Medium
PhishStrike Lab
A spoofed invoice email traced through a full malware delivery chain — CoinMiner, BitRAT, and AsyncRAT — down to their C2 domains and a Telegram exfil bot.
tools & stack

What I work with

SIEM · Log Analysis 01
SplunkSPLKQLElastic
Network Forensics 02
WiresharkCyberChef
Memory Forensics 03
VolatilityFTK ImagerRedlineStrings
Threat Intel · OSINT 04
VirusTotalShodanMITRE ATT&CKURLhausURLScan.ioMalwareBazaarVMRayEmail Header Analyzer
Disk Analysis 05
AutopsyWeb Cache View
Registry & Artifact Analysis 06
Registry ExplorerEvent Log ExplorerAppCompatCacheParser