VENOMOUSVIPER-LABS :: INITIALIZING LAB CONSOLE...
LOADING MODULES :: AD-LAB | CYBERLAB | VIPERKIT | VIPERAI INBOX
ACCESS LEVEL :: TIER-3 OPS
STATUS :: ONLINE
Stand by while the console loads…
[14:12:09] AD-LAB INFO New user test.tech created for GPO test
[14:13:44] AD-LAB INFO GPO 'LAB-Workstation-Baseline' linked to OU 'LAB-Workstations'
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
[14:12:09] AD-LAB INFO New user test.tech created for GPO test
[14:13:44] AD-LAB INFO GPO 'LAB-Workstation-Baseline' linked to OU 'LAB-Workstations'
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
[14:12:09] AD-LAB INFO New user test.tech created for GPO test
[14:13:44] AD-LAB INFO GPO 'LAB-Workstation-Baseline' linked to OU 'LAB-Workstations'
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:12:09] AD-LAB INFO New user test.tech created for GPO test
[14:13:44] AD-LAB INFO GPO 'LAB-Workstation-Baseline' linked to OU 'LAB-Workstations'
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
[14:12:09] AD-LAB INFO New user test.tech created for GPO test
[14:13:44] AD-LAB INFO GPO 'LAB-Workstation-Baseline' linked to OU 'LAB-Workstations'
[14:15:02] CYBERLAB WARN Snapshot taken on DETONATION-01 before sample run
[14:17:29] CYBERLAB INFO Wazuh agent check-in from DETONATION-01 (rule set updated)
[14:19:34] CYBERLAB WARN Suspicious PowerShell command observed (encoded payload)
[14:21:55] VIPERKIT INFO Case #23 opened: Ransomware alert on WIN10-CL01
[14:23:02] VIPERKIT INFO HUNT tab: suspicious process tree captured for review
[14:24:41] VIPERKIT INFO SWEEP tab: autoruns and scheduled tasks snapshot exported
[14:26:01] VIPERKIT INFO Case #23 updated – persistence removed on WIN10-CL01
[14:27:48] VIPERKIT INFO HARDEN tab: basic hardening checklist marked complete
[14:29:10] VIPERAI-INBOX INFO New email submitted from CLIENT-01 (subject: 'Outstanding invoice')
[14:30:47] VIPERAI-INBOX ALERT URL pattern flagged as suspected credential harvest
[14:31:19] VIPERAI-INBOX INFO User-safe explanation generated for help desk ticket notes
[14:33:02] CYBERLAB INFO PCAP capture rotated for DETONATION-01
[14:34:55] AD-LAB INFO Test account 'lab.audit' added to Sec-Group 'LAB-HelpDesk'
[14:36:21] AD-LAB INFO Password policy 'LAB-Default-Domain' complexity rules updated
[14:37:44] CYBERLAB INFO Network capture started on interface eth0 (DETONATION-01)
[14:39:02] VIPERKIT INFO Case #24 opened: Unwanted remote tool detected on WIN10-CL02
[14:41:29] VIPERKIT INFO PERSIST tab: suspicious registry run key identified
[14:43:34] VIPERAI-INBOX WARN Email attachment contains suspicious macro code
[14:45:55] AD-LAB INFO New group 'LAB-SecOps' created for security testing
[14:47:02] CYBERLAB ALERT Alert rule triggered: possible lateral movement detected
[14:48:41] VIPERKIT INFO CLEANUP tab: temporary files removed from user profile
[14:50:01] VIPERAI-INBOX INFO Sender domain reputation check: low trust score
[14:51:47] AD-LAB INFO GPO refresh triggered for OU 'LAB-Servers'
[14:53:12] CYBERLAB INFO Malware sample detonated in isolated sandbox
[14:55:29] VIPERKIT INFO Case #24 updated – persistence mechanism removed
[14:57:34] VIPERAI-INBOX ALERT Multiple URL redirects detected – likely phishing campaign
[14:59:10] AD-LAB INFO User 'lab.admin' successfully authenticated to LAB-DC01
[15:01:44] CYBERLAB WARN Unusual outbound connection attempt blocked by firewall
[15:03:02] VIPERKIT INFO HARDEN tab: Windows Defender real-time protection verified
[15:05:29] VIPERAI-INBOX INFO Email analysis complete – risk score: HIGH
[15:07:34] AD-LAB INFO Security group membership audit completed for OU 'LAB-Users'
[15:09:55] CYBERLAB INFO System snapshot created: DETONATION-01-clean-baseline
[15:11:02] VIPERKIT INFO Case #25 opened: Suspicious scheduled task on WIN10-CL03
[15:13:41] VIPERAI-INBOX WARN Attachment file hash matches known malware signature
[15:15:01] AD-LAB INFO OU structure updated – new child OU 'LAB-Test-Machines' created
[15:17:48] CYBERLAB INFO Sysmon event log exported for analysis
[15:19:10] VIPERKIT INFO HUNT tab: active network connections enumerated
[15:21:47] VIPERAI-INBOX INFO Link analysis complete – 3 suspicious URLs flagged
VENOMOUSVIPER LABS
Cybersecurity Portfolio · Systems & Security Engineer

Jeremy Tarkington - Security Portfolio

Systems/Security Engineer specializing in incident response, SIEM/EDR, and security automation. Explore my projects below.

Cybersecurity Portfolio
Lake Charles, LA

Projects

Infrastructure & Operations

INFRASTRUCTURE
Homelab / Docs
Server Documentation Pipeline

Two production homelab servers documented as sanitized, published references — a 17 TB storage/services host and a security/OSINT host — generated by a tool that verifies its own output before publishing.

BACKUP & RECOVERY
Resilience
Backup & Recovery Architecture

Four independent layers protecting a two-server homelab — encrypted file-level backups with append-only agents, weekly bare-metal system images, parity across the storage array, and off-site replication.

AI GOVERNANCE
Field Guide
Copilot · Gemini · ChatGPT · Claude

Security field guide for deploying Copilot, Gemini, ChatGPT, and Claude into client tenants — tier differences, admin console walkthroughs, and the permission pre-flight work that prevents AI oversharing incidents.

AWS DEPLOYMENT
Cloud & Hardening
Public Site on EC2

Deploying a public WordPress site on AWS EC2 with no SSH exposed to the internet, TLS at a reverse proxy, layered application hardening, and append-only off-site backups over a private mesh.

WORDPRESS
Build & Migration
Self-Hosted Publishing Stack

Building a 34-article archive on self-hosted WordPress — bulk content conversion, theme customisation, and what a WordPress export actually carries when you migrate hosts.

Security Tooling

VIPERSHADOW
Threat Intelligence
Dark Web Investigation Platform

Investigation-grade dark web intelligence platform. Multi-layer Tor scraping, IOC extraction, LLM-driven analysis grounded in evidence. Built for operators who need depth without enterprise pricing.

VIPERKIT
IR Toolkit
Incident Response Toolkit

Portable desktop IR toolkit that walks techs through Hunt → Persist → Sweep → Cleanup → Hardening, with case tracking, reports, and audit trails built for real MSP incidents.

VIPERDEN
Network Scanner
Deep Network Discovery & Vuln Scanner

On-demand network investigation platform. Drop a lightweight daemon on any network, run a deep scan, and get an evidence-backed map of every device — services, CVEs, classification, and site-to-site subnet discovery.

VIPERSCAN
Remote AV Scanner
Operator-Driven Endpoint AV Scanner

Self-hosted, operator-driven remote AV scanner for Windows fleets. Trigger silent on-demand scans through your RMM, parse results centrally, and manually quarantine, dismiss, or escalate each finding. Pluggable scanners and RMMs via YAML.

IT & Ops Tooling

VIPERMIGRATE
Migration Tool
Windows Workstation Migration

Portable .NET 8 desktop tool that captures a Windows workstation's complete configuration — software, browsers, printers, Wi-Fi, shortcuts — into an encrypted package and restores it on a new machine.

VIPERSHELL
PS Reference
PowerShell Command Reference

Interactive PowerShell command reference tool with search, category browsing, syntax highlighting, and copy-to-clipboard. Built as a standalone web app for quick command lookup during IR and admin tasks.

VIPERAI INBOX
AI Email Intel
AI-Powered Email & Phishing Analyzer

Local AI-powered phishing and attachment analyzer for real-world email tickets — drag and drop .eml/.msg to get technical findings, a user-friendly explanation, and clear recommended actions.

Labs & Detection

AD LAB
Core Range
Active Directory Range

Multi-VM AD lab used for Group Policy, auth workflows, and attack/defense practice in a safe, rebuildable environment.

CYBERLAB
Detonation
Security Tooling & Detonation Lab

Isolated cyber lab for safely detonating malware, capturing endpoint and network telemetry, and rehearsing analysis workflows with Wazuh, PCAPs, and scripted runbooks.

WAZUH RULES
SIEM/EDR
Custom Detection Rules

Custom Wazuh detection rules for identifying malicious PowerShell, persistence mechanisms, lateral movement, and credential theft. Tuned to reduce false positives while catching real threats.

12 DAYS OF CYBER
CTF
Holiday CTF Challenge Series

Progressive 12-day CTF with story-driven challenges covering encoding, hash cracking, log analysis, JavaScript deobfuscation, PowerShell malware, web recon, DNS tunneling, SQL injection, and more. Gated progression with flag-based unlocking.

Reference & Writing

CODE SAMPLES
Scripts
PowerShell, Bash & Python

Collection of security automation scripts and IR tools. PowerShell for Windows forensics, Bash for system analysis, and Python for threat hunting and data processing.

PS ONE-LINERS
Quick Reference
50+ PowerShell IR Commands

Comprehensive collection of PowerShell one-liners for incident response, forensics, AD security, and threat hunting. Downloadable reference guide.

CHECKLISTS
Templates
Downloadable Assessment & IR Templates

Full CMMC L2 (110 checks), CIS benchmarks, IR playbooks, and report templates. All checklists downloadable for real-world use.

WRITEUPS
HTB/THM
Case Studies & Technical Reports

Technical reports and case studies from HackTheBox, TryHackMe, and real-world engagements covering Active Directory exploitation, penetration testing, digital forensics, compliance (CMMC/NIST), and detection engineering.

Toolchain

firewall/
fortigate
watchguard
pfsense
opnsense
cisco-asa
meraki-mx
network/
cisco-catalyst
meraki
ubiquiti
engenius
managed-switches
vlans
vpn/
site-to-site
ipsec-ikev2
ssl-vpn
watchguard-mobile-vpn
wireguard
tailscale
edr-av/
defender-for-endpoint
crowdstrike
sophos
bitdefender
malwarebytes
huntress
siem/
wazuh
velociraptor
splunk
security-onion
sysmon
sigma
forensics/
caine
csi-linux
autopsy
volatility
kape
zimmerman-tools
wireshark
tcpdump
sysinternals
osint/
spiderfoot
sherlock
maigret
whonix
tor
identity/
active-directory
entra-id
hybrid-identity
entra-connect
samba-ad-dc
google-workspace
exchange-on-prem
linux-user-admin
rmm-remote/
connectwise
n-able
screenconnect
meshcentral
teamviewer
anydesk
rustdesk
rdp
ssh-terminal/
winscp
termius
tabby
ssh
backup/
veeam
axcient
n-able-backup
borg
rear
snapraid
healthchecks
scripting/
powershell
bash
python
fish
platforms/
windows-10
windows-11
windows-server
macos
ubuntu
debian
fedora
rhel
arch
raspberry-pi
cloud/
azure
aws
m365-admin
ai-platforms/
m365-copilot
gemini-workspace
chatgpt-enterprise
claude-enterprise
ollama
ai-governance/
purview-dspm
sensitivity-labels
restricted-content-discovery
data-access-governance
workspace-intelligence
dlp-irm
oauth-connector-scoping
scim
saml-sso
ai-self-hosted/
anythingllm
librechat
qdrant
openrouter
mcp
rag-pipelines
pci-dss
retail / point-of-sale
hipaa
medical practices
cjis
law enforcement
louisiana-gaming
casino gaming
cmmc-l2
defense supply chain
nist-800-171
defense supply chain
cis-benchmarks
hardening baselines

Certifications

CompTIA A+
Google IT Support
CompTIA Network+ In Progress
CompTIA Security+ In Progress
Jeremy Tarkington - Portfolio Terminal
Welcome to Jeremy Tarkington's Portfolio Terminal
Type 'help' for available commands or 'exit' to close
 
viper@labs:~$
💻 Try the Interactive Terminal!
Click the glowing "Terminal" button below to explore my skills and projects → Click here to dismiss