Skip to content

My personal journal of CTF writeups, threat hunting investigations, and KQL experiments. Raw logs, step-by-step notes, and lessons learned from hands-on blue team and incident response challenges.

License

Notifications You must be signed in to change notification settings

shoganaich/blue-journal

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

11 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Black Gradient Banner

Threat hunt investigations, raw logs, lessons, and a few dead ends along the way.


📚 What’s Inside

  • Writeups: Step-by-step investigations, findings, and walkthroughs for each public CTF or incident I participate in.
  • KQL Logs: Raw query experiments, pivots, and iterations—so you see what worked and what didn’t.
  • Templates: My personal templates for keeping writeups and notes consistent (and hopefully useful).

🤔 Why This Repository Exists

  • To document the real process—failed hunts, “aha!” moments, and learning pivots.
  • To help fellow learners (and my future self) find practical blue team references.
  • To make investigations more repeatable (and less mysterious).

📂 Contents

🏴‍☠️ CTF/Lab 📝 Description 📄 Writeup 📊 KQL Logs 🗒️ Notes (PDF)
Deep Access: The Adversary Multi-host CTF; persistence, lateral movement Coming soon Sorry I lost it Deep Access The Adversary.pdf
The Great Admin Heist Malware dropper, LOLBin, persistence hunt Coming soon KQL Logs The Great Admin Heist.pdf
More coming soon...

👨‍💻 About Me

Victor Cardoso (aka Shoganaich)
Cybersecurity student & intern • Learning by doing
GitHub | LinkedIn | Blog


⚖️ License

This repo and all its contents are released under the MIT License — feel free to learn, fork, and remix (at your own risk!).


🦖 Don’t ask.

About

My personal journal of CTF writeups, threat hunting investigations, and KQL experiments. Raw logs, step-by-step notes, and lessons learned from hands-on blue team and incident response challenges.

Topics

Resources

License

Stars

Watchers

Forks