Incident Response & Digital Forensics (M.S. Cybersecurity, University of Tulsa)
Built and applied NIST 800-61 aligned incident response playbooks to structure detection, containment, eradication, recovery, and lessons learned. Performed malware triage and forensic analysis using network and endpoint inspection tools to support investigation outcomes. Generated consistent analysis artifacts for case documentation, including observations about suspicious PowerShell payloads and obfuscation. • Created incident response playbooks following NIST 800-61 lifecycle stages. • Analyzed malware artifacts and suspicious process execution chains. • Investigated encoded PowerShell payloads, Base64 obfuscation, and LOLBin abuse. • Examined DNS/HTTP traffic patterns to identify command-and-control indicators.