Erick Cisneros
ContactResume
Directory
Overview
Experience
Investigations & Tooling
The Trophy Case
Education
Contact Me
Direct Inquiries
Back to Security Investigations & Tooling
Detection & Forensics

Threat Hunts & Labs

Technical investigations and labs from GitHub: standalone repositories and structured scenarios under Threat Hunting Projects.

Threat Hunting

Threat Hunt: Unauthorized TOR Usage

KQL-driven investigation across DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to detect TOR installation and C2-style network activity.

Read StudyGitHub
Monitoring

Microsoft Sentinel Workbooks

KQL workbooks for logon failures, malicious traffic, and map-based views with threat intelligence enrichment.

Read StudyGitHub
Incident Response

Azuki Import/Export Compromise

Incident report: RDP initial access, discovery, Defender tampering, persistence, Mimikatz, C2, Discord exfiltration, and MITRE mapping with KQL appendices.

Read StudyGitHub
Threat Hunting

CorpHealth: Traceback

Full traceback investigation from the Portfolio threat-hunting collection (see GitHub for the complete write-up).

Read StudyGitHub
MDE

Virus Detection & Device Isolation (MDE)

Lab: antivirus detections via KQL, device isolation, investigation package, network verification, and release — with evidence screenshots.

Read StudyGitHub
Incident Response

EmberForge // Source Leak

Incident Report & CTF Writeup: Source code exfiltration via MEGA, AnyDesk persistence, and Sysmon analysis.

Read StudyGitHub
© 2026 Erick Cisneros Ruballos
LinkedIn•GitHub•Direct Email