Fotios Nanos
SOC Analyst · Threat Detection & Investigation
"Transferring 15 years of musical discipline into cybersecurity operations."
SOC Analyst with active experience in alert triage, threat detection, and investigation workflows, escalating findings into incident response processes. Formally assessed as a Cybersecurity Specialist by BEST Institut Vienna. Also holds the HTB Certified Defensive Security Analyst (CDSA) certification, a hands-on forensic and incident-handling credential from Hack The Box.
Greek native · English fluent · German conversational · 15+ years as a classical guitarist ->
Certifications & Assessments
- SOC Level 1 Path TryHackMe, 100% complete
- Cybersecurity Specialist Assessment BEST Institut Vienna
-
CDSA (Certified Defensive Security Analyst) Certified, August 2026
7-day practical exam requiring investigation, log and network analysis, and incident handling reasoning across two simulated network compromises, ending with a commercial-grade written incident report.
-
CPTS (Certified Penetration Testing Specialist) In progress
Hack The Box offensive certification, in progress. Offensive complement to a defensive SOC background, covering enumeration, web attacks, Active Directory, and post-exploitation.
Technical Skills
Technical Writeups
Selected investigations across disk, memory, network, and cross-platform forensics.
Full Kill Chain: Public Web Application to Domain-Wide Compromise
Consolidated report tying all six Honeynet Collapse investigations into a single campaign: cross-stage credential reuse, an escalating anti-forensics pattern across three hosts, a consolidated MITRE ATT&CK kill chain, and root-cause analysis spanning five compromised systems.
Attack & Detection: AI Tooling Exploitation
Full offense-to-defense engagement: MCP/AI-tooling SSRF and RCE, Jupyter credential harvesting, and WebSocket exploitation, paired with detection content written for Sentinel (KQL), Suricata, and Zeek, mapped to MITRE ATT&CK.
macOS Forensics: TCC & Infostealer Persistence
APFS disk image analysis of a compromised macOS workstation: trojanized installer, TCC permission abuse, disguised LaunchAgent persistence, and credential-harvesting exfiltration.
Ransomware: MFT Analysis & OSINT Attribution
Metadata-only forensic image reconstruction of a ransomware incident via $MFT and $UsnJrnl, with threat-group attribution resolved through sandbox-based OSINT rather than IOC pattern matching alone.
Disk Forensics: Anti-Forensics & Data Exfiltration
E01 disk image investigation reconstructing a full exfiltration incident, including attacker log-service tampering and pivoting to registry and PowerShell-history artifacts that survive it.
Memory Forensics: Process Injection Chain
Volatility 3 analysis of a memory dump reconstructing a full attack chain from lateral tool arrival through process injection, shellcode identification, and live network pivoting.
Initial Access to Lateral Movement
WordPress webshell delivery through SSH-key theft to root, followed by Windows lateral movement via scheduled-task hijack, LSASS dumping, and Shimcache recovery after log clearing.
SIEM & SOC Investigations
Volt Typhoon: Intrusion & Domain Compromise
Six-day living-off-the-land intrusion reconstructed from SIEM telemetry after the attacker cleared all event logs: identity-portal abuse, full domain credential extraction, web-shell persistence, and netsh relay cleanup.
BlackSun: PowerShell Kill Chain to Encryption
Full ransomware chain in Splunk from a single obfuscated PowerShell command: Defender disable, tunnel-based dropper delivery, SYSTEM scheduled task, and DNS-based C2 detection.
Finance Workstation: Credential Theft to Persistence
Sysmon investigation of a finance endpoint: repeated browser-credential harvesting, HTTP C2, targeted Defender signature suppression via WMI, and vendor-masquerading scheduled-task persistence.
Projects
Small Python security tools, AI-assisted, built to automate recurring analysis tasks.