Skip to content
View Fynnesse's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Fynnesse

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Fynnesse/README.md

Jeremiah Asagba

LinkedIn Security+ Network+

I'm a security analyst based in Manchester, UK, working toward a Tier 1 SOC role.

Most of what's here is documentation rather than code. I investigate things in live cloud environments and write up how I did it, including the parts that went wrong. I hold an MSc in Cybersecurity Management, Security+ and Network+, and two years of IT support experience before this.

Currently working through a 12-week cloud security track, publishing one documented investigation a week.


Cloud Security Investigations

Documented investigations in a live multi-user Azure tenant. Each one covers method, evidence and severity-ranked remediation. → security-portfolio

# Investigation Focus
1 Tracing a Non-Compliant Azure Deployment to an Audit-Only Policy Governance forensics, Azure Policy, deployment audit trail
2 Reconstructing an OAuth Consent-Phishing Kill Chain Entra ID, app registrations, OAuth consent abuse

Lab Builds

Project What I built Tools
SOC Automation Lab Detection rules for credential-dumping activity and an end-to-end SOAR pipeline from alert to case creation Wazuh, Shuffle, TheHive, VirusTotal
Active Directory Lab A virtualised AD environment with centralised logging, attacked and then detected Windows Server, Splunk, Sysmon, Atomic Red Team, Hydra
Malware Analysis Lab Static analysis of a malicious document through to C2 identification and a findings report REMnux, rtfdump, scdbg, VirusTotal
Network Analysis Lab Traffic monitoring and attack detection Wireshark

Tools I've actually used

Nothing listed here that isn't behind a project above.

Area Tools
Cloud & identity Azure · Entra ID · Conditional Access · Azure Policy · Microsoft Graph · RBAC · Active Directory · AWS (IAM, EC2, S3, VPC, CloudTrail)
Detection & response Splunk · Wazuh · Microsoft Defender for Endpoint · TheHive · Shuffle · Sysmon · VirusTotal
Analysis & forensics REMnux · Wireshark · Nmap · KQL · PowerShell
Frameworks MITRE ATT&CK · NIST CSF

Certifications & education

CompTIA Security+ Renewed 2026 Verify
CompTIA Network+ Renewed 2026 Verify
CompTIA CySA+ Expected December 2026
TryHackMe SAL1 Expected December 2026
MSc Cybersecurity Management University of Law, Manchester · 2025
BSc Computer Science Babcock University, Nigeria · 2021

Pinned Loading

  1. security-portfolio security-portfolio Public

    Documented cloud security investigations in a live Azure tenant: method, evidence and remediation.

    1

  2. SOC-Automation-Lab SOC-Automation-Lab Public

    Wazuh detection rules and a Shuffle SOAR pipeline automating alert triage into TheHive case creation.

    1

  3. Active-Directory-Lab Active-Directory-Lab Public

    A virtualised AD environment with Splunk and Sysmon logging, attacked with Atomic Red Team and detected.

  4. Malware-Analysis-w-REMnux-Lab Malware-Analysis-w-REMnux-Lab Public

    Static analysis of a malicious RTF document through to C2 identification, with a full findings report.

    1

  5. Network-Analysis-Lab Network-Analysis-Lab Public

    Network traffic monitoring and attack detection with Wireshark.