Skip to content

Repository files navigation

🛡️ Incident Response Simulation: Phantom Credentials

This project simulates a real-world cybersecurity incident involving phishing, VPN credential theft, and lateral movement. It demonstrates how a security team might detect, investigate, contain, and remediate a credential-based attack.


🧠 Scenario Summary

An attacker phishes an employee at Phantom Consulting Group and gains VPN access. They pivot through the network using RDP, access financial files, and attempt lateral movement.


🔍 What’s Inside

  • scenario.md — Attack narrative and timeline
  • logs/ — Simulated VPN, firewall, RDP, and event logs
  • analysis/incident_timeline.md — Log analysis and timeline of the attack
  • response_plan.md — Response actions, containment steps, and lessons learned
  • evidence/ — Placeholder for screenshots or forensic artifacts (if added)

🛠️ Skills Demonstrated

  • Incident Response Lifecycle (Detect, Contain, Eradicate, Recover)
  • Log Analysis (VPN, RDP, Firewall, Event Logs)
  • Threat Investigation & Documentation
  • Security Recommendations & Policy Improvements

📁 How to Use

Clone the repo and explore each file step-by-step. Use this simulation as a tabletop exercise, SOC analyst practice, or educational case study.


🚀 Author

Damian Lee
CompTIA Security+ | Google Cybersecurity Certificate
Oakland, CA | [LinkedIn]https://(www.linkedin.com/in/damian-lee-78b32782?lipi=urn%3Ali%3Apage%3Ad_flagship3_profile_view_base_contact_details%3BHqAejxE5R46tMgk9mNDBJA%3D%3D) | Cybersecurity Portfolio

About

Simulated incident response to phishing, credential theft, and lateral movement attack.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors