Fotios Nanos

Fotios Nanos

SOC Analyst · Threat Detection & Investigation

"Transferring 15 years of musical discipline into cybersecurity operations."

SOC Analyst with active experience in alert triage, threat detection, and investigation workflows, escalating findings into incident response processes. Formally assessed as a Cybersecurity Specialist by BEST Institut Vienna. Also holds the HTB Certified Defensive Security Analyst (CDSA) certification, a hands-on forensic and incident-handling credential from Hack The Box.

EU Citizen CDSA Certified

Greek native · English fluent · German conversational · 15+ years as a classical guitarist ->

Certifications & Assessments

  • SOC Level 1 Path TryHackMe, 100% complete
  • Cybersecurity Specialist Assessment BEST Institut Vienna
  • CDSA (Certified Defensive Security Analyst) Certified, August 2026

    7-day practical exam requiring investigation, log and network analysis, and incident handling reasoning across two simulated network compromises, ending with a commercial-grade written incident report.

  • CPTS (Certified Penetration Testing Specialist) In progress

    Hack The Box offensive certification, in progress. Offensive complement to a defensive SOC background, covering enumeration, web attacks, Active Directory, and post-exploitation.

Technical Skills

Daily operations
Microsoft Sentinel Defender XDR CrowdStrike Falcon ArcSight Splunk KQL Incident Triage & Reporting
Forensics & detection engineering
Volatility 3 KAPE Autopsy Wireshark / tshark MITRE ATT&CK Suricata / Zeek Python

Technical Writeups

Selected investigations across disk, memory, network, and cross-platform forensics.

Full Campaign Reconstruction · Honeynet Collapse, Stages 1-6

Full Kill Chain: Public Web Application to Domain-Wide Compromise

Consolidated report tying all six Honeynet Collapse investigations into a single campaign: cross-stage credential reuse, an escalating anti-forensics pattern across three hosts, a consolidated MITRE ATT&CK kill chain, and root-cause analysis spanning five compromised systems.

Read the full report ->
HTB Season 11 · DevHub

Attack & Detection: AI Tooling Exploitation

Full offense-to-defense engagement: MCP/AI-tooling SSRF and RCE, Jupyter credential harvesting, and WebSocket exploitation, paired with detection content written for Sentinel (KQL), Suricata, and Zeek, mapped to MITRE ATT&CK.

SSRF / RCE Detection Engineering Offense + Defense
Honeynet Collapse · Stage 6

macOS Forensics: TCC & Infostealer Persistence

APFS disk image analysis of a compromised macOS workstation: trojanized installer, TCC permission abuse, disguised LaunchAgent persistence, and credential-harvesting exfiltration.

macOS Forensics Persistence Analysis
Honeynet Collapse · Stage 5

Ransomware: MFT Analysis & OSINT Attribution

Metadata-only forensic image reconstruction of a ransomware incident via $MFT and $UsnJrnl, with threat-group attribution resolved through sandbox-based OSINT rather than IOC pattern matching alone.

Ransomware Threat Attribution OSINT
Honeynet Collapse · Stage 4

Disk Forensics: Anti-Forensics & Data Exfiltration

E01 disk image investigation reconstructing a full exfiltration incident, including attacker log-service tampering and pivoting to registry and PowerShell-history artifacts that survive it.

Disk Forensics Anti-Forensics
Honeynet Collapse · Stage 3

Memory Forensics: Process Injection Chain

Volatility 3 analysis of a memory dump reconstructing a full attack chain from lateral tool arrival through process injection, shellcode identification, and live network pivoting.

Memory Forensics Process Injection
Honeynet Collapse · Stages 1-2

Initial Access to Lateral Movement

WordPress webshell delivery through SSH-key theft to root, followed by Windows lateral movement via scheduled-task hijack, LSASS dumping, and Shimcache recovery after log clearing.

Web Exploitation Lateral Movement

SIEM & SOC Investigations

Projects

Small Python security tools, AI-assisted, built to automate recurring analysis tasks.

Domain Analyzer
OSINT reconnaissance + LLM-generated reporting
GitHub ->
Vuln-Report-AI
Nmap/Nikto/SQLMap output -> structured reports
GitHub ->
PCAP Analysis Projects
Structured network traffic forensics
GitHub ->
Brute-Force Detector
Real-time login-attempt monitoring & alerting
GitHub ->

Let's Connect

Feel free to reach out for professional inquiries or technical discussion.