// defense by day, offense by training

Hi, I'm Joshua Mitchum.

I spend my days triaging real intrusions in a multi-tenant SOC, and my nights running the exact attack chains those alerts are built to catch — Active Directory attack paths, adversary simulation, and detection engineering informed by an attacker's perspective.

> I leverage AI to spin up environments in seconds, keeping my focus where it actually matters: real-world offensive and defensive operations.

Penetration Testing SOC Detection Engineering PNPT · PJPT · eJPT OSCP — in progress

01 About

My tech journey started on the workbench as a Junior Technician, doing hands-on hardware repairs and deep troubleshooting. Taking a device in its absolute worst, broken state and bringing it back to life for a client gave me a ground-level understanding of how systems work when everything goes wrong. Over time, I transitioned into a Senior Windows Technician role. My focus shifted from hardware teardowns to working directly with clients — setting up NAS backup systems, configuring firewalls, and mentoring junior technicians on the team. All the while, I was spending my spare hours studying and preparing for my true passion: cybersecurity.

That studying paid off with a SOC analyst role at a managed security provider, and it turned out triaging real alerts against real attackers was exactly the deep end I'd been chasing. But the more intrusions I investigated, the more I wanted to be on the other side of them — not just reading the logs an attacker left behind, but understanding the decisions that led there. So I started building my own Active Directory attack labs on nights and weekends, chasing that same feeling I had back on the workbench — taking something apart until I actually understood it, not just until it worked again.

  • 7+Years in IT overall
  • 20+Client tenants covered
  • 2Certs in progress — OSCP & CRTP

02 Resume

Experience

  1. 2023 — Mar 2026

    SOC Analyst

    Northern Technologies Group (NTG) — Managed Security Service Provider

    • Authored and drove adoption of a BloodHound CE / AzureHound CE Quarterly Identity Attack Path Review program across 20+ client tenants — cut the monthly privileged-account audit review from a full week to a single day.
    • Built custom KQL detection rules in Microsoft Sentinel mapped to MITRE ATT&CK, covering credential stuffing, brute-force patterns, lateral movement, authentication bypasses/config changes, and ACL/permission abuse.
    • Investigated Microsoft 365 and Entra ID abuse — privileged role misuse, delegated permission exploitation, sign-in anomalies, over-privileged accounts — across 20+ client tenants, with formal remediation guidance.
    • Proposed and designed a Kasm Workspaces malware detonation sandbox, approved by SOC management, for isolated dynamic analysis of suspicious files and URLs.
    • Performed static and dynamic malware analysis (FLARE VM, Ghidra, sandbox detonation) to extract IOCs, map TTPs, and produce detection logic from real samples.
    • Engineered Python automation for EDR compliance gap analysis across FortiEDR and Halcyon EDR, surfacing endpoint coverage blind spots across 20+ tenants that would otherwise require manual auditing.
    • Triaged and investigated alerts across a 24x7 multi-tenant SOC, consistently meeting a required minimum of 20 alerts triaged per tool, per shift, across Sentinel, Splunk, FortiEDR, Halcyon EDR, and FortiMail.
    • Authored additional internal security proposals adopted by SOC management, including a centralized phishing mailbox standardizing analyst triage across all managed tenants.
  2. 2021 — 2023

    Junior Technician → Senior Windows Technician

    Carbondale Computer Repair

    • Progressed from Junior Technician to Senior Windows Technician over two years, taking on increasing ownership of infrastructure, training, and escalated technical work.
    • Administered a custom-built, in-house ticketing platform managing workflow and issue tracking for all incoming service requests.
    • Configured and maintained network firewall infrastructure, managing rule sets and access policies across client and internal networks.
    • Performed component-level hardware repair — soldering and board-level diagnostics — on laptops, desktops, and peripherals; trained and mentored incoming technicians.
  3. 2019 — 2021

    Junior Technician

    Fyxit

    • Diagnosed and resolved Windows OS issues, conducted virus and malware cleanup, and performed data recovery on damaged or corrupted drives.
    • Performed small electronics and mobile device repairs; managed inventory tracking and parts procurement for repair operations.

Certifications

PNPT Practical Network Penetration Tester TCM Security
PJPT Practical Junior Penetration Tester TCM Security
eJPT Junior Penetration Tester INE Security
OSCP Offensive Security Certified Professional OffSec — In Progress
CRTP Certified Red Team Professional Altered Security — In Progress

Skills

Offensive / AD

BloodHound CE, AzureHound CE, Mimikatz, Impacket, Rubeus, CrackMapExec, PowerView, Evil-WinRM, Responder, Metasploit, Burp Suite — Kerberoasting, AS-REP Roasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, forest trust exploitation, PSRemoting backdoors

SIEM & Detection

Microsoft Sentinel (KQL — advanced), Splunk (SPL), Security Onion, FortiEDR, Halcyon EDR, FortiMail, Greenbone, Nessus, Wazuh, Zabbix

Detection Frameworks

MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, NIST 800-61, NIST CSF, CVSS, PCI-DSS, HIPAA

Cloud / Identity

Microsoft Entra ID (Azure AD), M365 investigations, OfficeActivity log analysis, sign-in anomaly review, conditional access review, privileged role abuse investigation

Malware Analysis

FLARE VM, Ghidra, IDA Pro — static and dynamic analysis, IOC extraction, TTP mapping

Web Security

OWASP Top 10, Burp Suite, SQLMap, Nikto — application enumeration, injection, authentication bypass

Scripting

Python, PowerShell, Bash — custom tooling, API integration, automation, log enrichment

Infrastructure

Docker, Docker Compose, Vagrant, VirtualBox, pfSense, Debian Linux, systemd — lab build and hardening

Hardware / Field IT

Component-level soldering and board-level repair, PC/laptop/mobile diagnostics and rebuild, firewall configuration, ticketing system administration, data recovery

Platforms

HackTheBox (Dante Pro Lab), OffSec Proving Grounds, TryHackMe

Education

Bachelor of Science, Cybersecurity

University of Maryland Global Campus (UMGC)

Key Projects

Personal Lab

Active Directory Attack Lab

Full attack chain practice environment — Kerberoasting, AS-REP Roasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, and forest trust exploitation — used to build MITRE ATT&CK-mapped detection logic and understand attacker dwell patterns. This is the lab behind the Attack Lab section below.

In Progress

Zentrix — Pentest Productivity Tool

Python/Qt desktop app with an embedded terminal, tabbed session navigation, and a lightweight AI model that auto-generates structured notes from terminal sessions — built to cut engagement documentation overhead.

Download PDF version

03 Badges & Certifications

Click a badge to verify it, or view it larger.

04 Attack Lab

COMING SOON

Walk through a real attack, live.

This section will let you launch my Active Directory Attack Lab directly from the browser and follow the exact attack chain I ran — Kerberoasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, forest trust exploitation — with a shortcut into a read-only Splunk view of the logs it generated, plus my written analysis alongside it. No recordings, no slideshow: the actual environment, the actual telemetry.

  • Launch a scoped, disposable copy of the AD Attack Lab on demand
  • Desktop shortcut into Splunk showing the attack's log trail
  • My write-up displayed side-by-side with the environment

05 Contact

Open to opportunities in offensive security and detection engineering.