Cybersecurity · Singapore

Ashton Ang.

I work out what happened.

Cybersecurity student in Singapore. Give me a pile of logs and I'll tell you the story in them, including the parts I got wrong on the way.

Competition result · August 2026

Kaspersky{CTF} 2026

Competed with NxT, representing ITE College West. The team solved 9 challenges across pwn, reverse engineering, cryptography, misc, and AI.

See the team result & write-ups
69th
Asia regional league
736
team points
9
team solves
About

I'm a cybersecurity student at the Institute of Technical Education in Singapore, and I learn by building. I care more about understanding a system than about being able to say I used it.

Focus
Log analysis, incident investigation, network security
Working in
Python · Shell · SQL
Credentials
Fortinet NSE 3 · Google Cybersecurity · Splunk Core · TryHackMe SOC Level 1
Looking for
A cybersecurity internship
Try it

Twelve lines from an auth.log. Click the ones that worry you, then run the rules and see what a small detection engine would have caught, and what it would have missed.

auth.log · 12 lines click the ones that worry you
Featured projects All projects
Detection & response

Splunk BOTSv1

Two write-ups working through Splunk's own 33-million-event BOTSv1 training dataset as the defender, a website defacement and a ransomware outbreak on the same simulated network.

  • Splunk
  • SIEM
  • Log analysis
  • Incident investigation
  • Ransomware
Splunk reporting 33,413,777 indexed events in the BOTSv1 dataset
All 33,413,777 events, before any of them meant anything.
Detection & response

TryHackMe: Boogeyman 3

A capstone investigation from TryHackMe's SOC Level 1 path. One fake PDF on the CEO's machine, followed through Kibana to a DCSync and ransomware on the domain controller two hours later.

  • Elastic
  • Kibana
  • KQL
  • Incident investigation
  • MITRE ATT&CK
TryHackMe Boogeyman 3 room banner, a shadowy figure with a scythe outside a door marked CEO Room
Boogeyman 3, a capstone room in the SOC Level 1 path.
Tooling & automation

Mini SIEM

A Python tool that parses a Linux auth log once and runs four detection rules over it, then prints a ranked alert report.

  • Python
  • Detection rules
  • Log parsing
  • Regex
  • SOC
Terminal output showing the ranked alert report, grouped by detection rule
The ranked report, loudest rule first.

Building something, hiring, or curious?

Get in touch