Skip to content

Writeups

Welcome to Yao Amebe's hands-on security labs. This is a list of CTF writeups and projects where I set up lab environments, simulate attacks, and detect and investigate them.

  • SOC Detection Lab


    This lab simulates and detects real-world attack techniques (Kerberoasting, Credential Dumping) in a self-built Active Directory environment with a Splunk SIEM.

  • Insider Threat IR Lab


    This lab follows the NIST Incident Response process to investigate a simulated insider-threat data leak, from AD audit policy setup and a honey file, through log analysis, to containment and lessons learned.

  • SANS Holiday Hack Challenge 2025 ↗


    My write up of the SANS Holiday Hack challenge 2025.