This project simulates a real-world cybersecurity incident involving phishing, VPN credential theft, and lateral movement. It demonstrates how a security team might detect, investigate, contain, and remediate a credential-based attack.
An attacker phishes an employee at Phantom Consulting Group and gains VPN access. They pivot through the network using RDP, access financial files, and attempt lateral movement.
- scenario.md — Attack narrative and timeline
- logs/ — Simulated VPN, firewall, RDP, and event logs
- analysis/incident_timeline.md — Log analysis and timeline of the attack
- response_plan.md — Response actions, containment steps, and lessons learned
- evidence/ — Placeholder for screenshots or forensic artifacts (if added)
- Incident Response Lifecycle (Detect, Contain, Eradicate, Recover)
- Log Analysis (VPN, RDP, Firewall, Event Logs)
- Threat Investigation & Documentation
- Security Recommendations & Policy Improvements
Clone the repo and explore each file step-by-step. Use this simulation as a tabletop exercise, SOC analyst practice, or educational case study.
Damian Lee
CompTIA Security+ | Google Cybersecurity Certificate
Oakland, CA | [LinkedIn]https://(www.linkedin.com/in/damian-lee-78b32782?lipi=urn%3Ali%3Apage%3Ad_flagship3_profile_view_base_contact_details%3BHqAejxE5R46tMgk9mNDBJA%3D%3D) | Cybersecurity Portfolio