Ho Quoc Thai portrait

No system is unbreakable — only unexplored.

Hi, this is

Quoc Thai

Network Security Student | SOC Analyst in Training | CTF Player

I am a cybersecurity learner focusing on SOC analysis, log investigation, threat detection, and hands-on security labs.

I like to document what I learn along the way: small experiments, CTF write-ups, and the occasional late-night debugging session.

SOC Alert triage
SIEM Wazuh labs
CTF Write-ups

About

Ho Quoc Thai profile photo

I am a network security student currently training to become a SOC Analyst. My learning path focuses on analyzing security events, investigating logs, understanding attacker techniques, and building practical detection skills through labs, CTFs, and real-world security scenarios.

I enjoy learning by doing: building labs, solving CTF challenges, writing reports, documenting findings, and improving my ability to investigate security incidents.

Threat Detection Log Investigation Digital Forensics Security Labs

Skills

Technical skill areas

Organized around SOC work, operating system fundamentals, security practice, and tools.

~/portfolio/skills.workspace
01

Capability map

Compact overview of core security skills, evidence, and related technologies.

SOC & Blue Team

Intermediate

Alert triage, log review, IOC validation, MITRE mapping.

Wazuh labs Detection notes Incident reports

Operating Systems

Intermediate

Windows/Linux log reading, shell workflow, service inspection.

Event logs Linux CLI Shell basics

Security Practice

Learning

OSINT, web testing, malware behavior notes, CTF methodology.

CTF write-ups OSINT notes Web labs

Investigation Workflow

Proficient

Discovery, packet review, SIEM context, practical reporting.

Recon Traffic analysis Report writing
02

Toolbox matrix

Tools arranged by investigation workflow instead of text-heavy lists.

Discover Capture Detect Report
Nmap
Nmap Discovery
Wireshark
Wireshark Packets
Wazuh
Wazuh SIEM
Burp Suite
Burp Suite Web
Linux CLI
Linux CLI Shell
MITRE ATT&CK
MITRE Mapping
06Core tools
04Workflows
LabsEvidence based

Projects

Hands-on cybersecurity projects

Practical labs and documentation focused on investigation, detection, and evidence-based analysis.

Infrastructure Project

Designing and Implementing High Availability (HA) Solutions for Network Services on Windows Server 2019

Designed and implemented a high availability solution for Windows Server 2019 network services, focusing on redundancy, continuity, and resilient service deployment.

02/2026 - 05/2026

Windows Server High Availability Failover Network Services
System Security

Deploying and Evaluating the Security of a Linux System Using Lynis

Deployed a Linux environment and used Lynis to audit, assess, and improve system security through hardening and configuration review.

01/2026 - 05/2026

Linux Security Lynis Hardening Audit
Monitoring Project

Designing and Implementing a Network Monitoring System with LibreNMS

Built a network monitoring system using LibreNMS to observe device health, network availability, and operational status in a centralized dashboard.

01/2026 - 05/2026

LibreNMS Monitoring SNMP Observability
Detection Project

Design and Implementation of an AI-Based Network Intrusion Detection System Using pfSense Firewall and ELK Stack

Designed an intrusion detection workflow combining pfSense and the ELK Stack to collect, analyze, and visualize network security events for anomaly detection.

10/2025 - 01/2026

pfSense ELK Stack IDS Network Security

CTF Write-ups

Challenge notes and solving methodology

Blog-style cards for documenting the problem, evidence, exploitation path, and lessons learned.

~/writeups/CTF_WRITEUPS.log
ctf@hackerlab:~/writeups$ cat CTF_WRITEUPS.log
[REQ-01: FILE_VULNERABILITY]

Type: Web Exploitation

File Upload Vulnerability Lab

Analyzing weak upload validation, identifying execution paths, and documenting controlled exploitation steps.

Execute: writeup.sh
[REQ-02: REGISTRY_INVEST]

Type: Digital Forensics

Windows Registry Investigation

Reviewing registry artifacts, deleted traces, persistence indicators, and evidence extraction workflow.

Execute: writeup.sh
[REQ-03: OSINT_SEARCH]

Type: OSINT

Public Source Investigation

Using public metadata, visible clues, and structured search methods without crossing privacy boundaries.

Execute: osint_lookup.sh
[REQ-04: BINARY_ANALYSIS]

Type: Reverse Engineering

Basic Binary Analysis

Reading program behavior, identifying strings, checking file formats, and building a repeatable analysis process.

Execute: binary_disasm.exe

GHI CHÚ BẢO MẬT

Bản đồ cảnh báo an ninh mạng

Mỗi điểm đỏ đại diện cho một bài viết, lỗ hổng bảo mật hoặc sự kiện tấn công đáng chú ý. Nhấp vào cảnh báo để xem chi tiết phân tích.

~/threat_ops/global_alerts.conf
Critical United States
Web Exploitation

Critical file transfer vulnerability exploitation

Large-scale exploitation of a file transfer platform vulnerability led to widespread incident response.

May 2023 CVE-2023-34362
Active alert node Hover to inspect incident

Learning Roadmap

Cybersecurity learning path

A practical path toward SOC analysis, detection engineering fundamentals, and stronger portfolio documentation.

01

Networking fundamentals

TCP/IP, routing, switching, DNS, HTTP, ports and basic network troubleshooting.

02

Linux and Windows fundamentals

Operating system basics, users, services, permissions, logs and command-line workflow.

03

Log analysis and SIEM basics

Collecting, reading and correlating security logs through SIEM investigation workflows.

04

SOC alert triage

Classifying alerts, reviewing context, reducing false positives and escalating real incidents.

05

MITRE ATT&CK and threat detection

Mapping behavior to tactics and techniques, then improving detection coverage.

06

Digital forensics and malware basics

Reviewing artifacts, persistence traces, file behavior, suspicious commands and IOCs.

07

CTF practice and project documentation

Solving challenges, writing reports, documenting evidence and building repeatable notes.

08

Build a strong SOC Analyst portfolio

Publishing labs, write-ups, detection notes and practical investigation projects.

Contact

Connect and collaborate

For projects, write-ups, labs, and cybersecurity learning documentation.

Always learning. Always investigating. Always improving.