Cybersecurity Research Portfolio

Sergiu Vincze

Junior SOC analyst and full-stack developer based in Belgium. This portfolio documents real hands-on cybersecurity work — live threat investigations, malware reverse engineering, payload decoding, and EU abuse reporting. Every case here is a real attack, investigated passively from start to finish.

Threat Intelligence Passive OSINT Malware Analysis PS1 Payload Decoding Social Engineering Detection IOC Extraction MITRE ATT&CK Mapping EU Abuse Reporting ASN / WHOIS Attribution Python RAT Analysis HAR / JS Bundle Forensics GDPR Violation Analysis
20Active Cases Investigated
4Obfuscation Layers Broken
8Takedowns Confirmed via Report
3Live C2 / Malware Servers Found
15+IOC Types Extracted
EUReported: FCCU · EUIPO · EC3
Confirmed Takedowns
✓ PAYLOAD OFFLINE 2026-08-18
Case 001 — Amadey Dropper
build2_sava.exe · 404 · AS202412 dead
Full Report →
✓ SERVER OFFLINE 2026-08-18
Case 009 — bpost-secure.com
44 domains · AS208185 null-routed
Full Report →
✓ DOMAIN SEIZED 2026-08-17
Case 010 — basicmodoralo.com
ClientHold · NameSilo #468369 · 3,309 URLs
Full Report →
✓ ALL 3 GENS SEIZED 2026-08-18
Case 013 — MONOPOLY GUARD v3
282119 · 282032 · 283101 · DNS removed
Full Report →
✓ INFRASTRUCTURE DOWN 2026-08-19
Case 007 — Netflix PhaaS Kit
228 domains · 69HOST AS205397 · HTTP 000
Full Report →
✓ FULL TAKEDOWN 2026-08-19
Case 015 — Klarna Refund PhaaS
Belgian school staff · domain + server dead
Full Report →
✓ DOMAIN DOWN 2026-08-25
Case 011 — La Banque Postale PhaaS
support-postal.com HTTP 000 · server still up
Full Report →
✓ C2 OFFLINE 2026-08-25
Case 018 — EvilTokens PhaaS
techroboticslabmade.com C2 · HTTP 000
Full Report →
Category: Threat Intelligence & OSINT

Live Investigations

Real attacks investigated passively, fully documented A to Z.
Active Portfolio

More cases and reports across penetration testing, vulnerability research, and SOC exercises will be published here as investigations are completed.

Open DeepSeek Isolation Lab
Demonstrated Skills
🔍

Passive OSINT & Threat Intel

  • WHOIS & ASN attribution
  • Certificate transparency logs
  • Threat feed analysis (URLhaus, OpenPhish)
  • HTTP banner grabbing
  • Public Shodan/Censys data
🦠

Malware / Payload Analysis

  • PE32+ static binary analysis (objdump, strings, entropy)
  • Export/import table analysis
  • PowerShell deobfuscation
  • XOR / base64 / char-array decryption
  • Python RAT capability mapping
📡

C2 Infrastructure Analysis

  • C2 endpoint fingerprinting
  • API structure reverse engineering
  • Hardcoded credential extraction
  • Live server confirmation
  • Bulletproof hosting attribution
🛡️

Detection Engineering

  • MITRE ATT&CK technique mapping
  • IOC extraction for SIEM ingestion
  • Mutex / persistence indicator logging
  • Network behavior pattern analysis
  • AMSI bypass technique documentation
⚖️

EU Abuse Reporting

  • FCCU Belgium reporting process
  • EC3 / Europol cybercrime reporting
  • Cloudflare registrar abuse workflow
  • EUIPO anti-phishing coordination
  • Structured technical evidence packages
💻

Development Background

  • Full-stack PHP (8.3) / MariaDB
  • Python scripting and analysis
  • Linux shell / nginx / systemd
  • JavaScript / web application logic
  • Security-conscious architecture design
Investigation Methodology

All investigations are conducted using passive OSINT only — no unauthorized system access, no active exploitation. Legally performed from Belgium, EU. Findings are submitted to relevant authorities for takedown and prosecution coordination.

DNS / WHOIS / ASNDomain registration dates, registrar, hosting ASN, upstream providers
HTTP Header AnalysisServer fingerprinting via passive HEAD requests (browser-equivalent)
Threat Feed TriageURLhaus, OpenPhish, PhishTank — live feed analysis for fresh IOCs
Static File AnalysisPublic files fetched and analyzed statically — no execution, no sandboxes needed for passive recon
Payload DecodingManual obfuscation layer stripping: char-arrays, XOR, base64, UTF-16 encoding chains
Certificate Transparencycrt.sh subdomain enumeration on malicious parent domains

Looking to hire a junior SOC analyst or security researcher?

Based in Belgium. Available for junior SOC analyst roles, threat intelligence positions, or security engineering internships. Every case on this page is a real investigation — not a CTF, not a lab environment — real active malware, decoded end to end.

SevinOS BLE Radar