Cybersecurity · Singapore

Ashton Ang.

I work out what happened.

Cybersecurity student in Singapore. Give me a pile of logs and I'll tell you the story in them, including the parts I got wrong on the way.

About

I'm a cybersecurity student at the Institute of Technical Education in Singapore, and I learn by building. I care more about understanding a system than about being able to say I used it.

Focus
Log analysis, incident investigation, network security
Working in
Python · Shell · SQL
Credentials
Fortinet FCF · Google Cybersecurity · Splunk Core
In progress
TryHackMe SOC Level 1
Looking for
A cybersecurity internship
Featured projects All projects
Detection & response

Splunk BOTSv1

Two write-ups working through Splunk's own 33-million-event BOTSv1 training dataset as the defender, a website defacement and a ransomware outbreak on the same simulated network.

  • Splunk
  • SIEM
  • Log analysis
  • Incident investigation
  • Ransomware
Splunk reporting 33,413,777 indexed events in the BOTSv1 dataset
All 33,413,777 events, before any of them meant anything.
Tooling & automation

Mini SIEM

A Python tool that parses a Linux auth log once and runs four detection rules over it, then prints a ranked alert report.

  • Python
  • Detection rules
  • Log parsing
  • Regex
  • SOC
Terminal output showing the ranked alert report, grouped by detection rule
The ranked report, loudest rule first.
Offensive security

Hack The Box: Oopsie

My first full Hack The Box machine, taken from a guest cookie to a shell on the box.

  • Hack The Box
  • Web exploitation
  • Burp Suite
  • Reverse shell
  • Linux
A reverse shell on the target box running as the www-data user
The reverse shell landing as www-data.

Building something, hiring, or curious?

Get in touch