// defense by day, offense by training
Hi, I'm Joshua Mitchum.
I spend my days triaging real intrusions in a multi-tenant SOC, and my nights running the exact attack chains those alerts are built to catch — Active Directory attack paths, adversary simulation, and detection engineering informed by an attacker's perspective.
> I leverage AI to spin up environments in seconds, keeping my focus where it actually matters: real-world offensive and defensive operations.
01 About
My tech journey started on the workbench as a Junior Technician, doing hands-on hardware repairs and deep troubleshooting. Taking a device in its absolute worst, broken state and bringing it back to life for a client gave me a ground-level understanding of how systems work when everything goes wrong. Over time, I transitioned into a Senior Windows Technician role. My focus shifted from hardware teardowns to working directly with clients — setting up NAS backup systems, configuring firewalls, and mentoring junior technicians on the team. All the while, I was spending my spare hours studying and preparing for my true passion: cybersecurity.
That studying paid off with a SOC analyst role at a managed security provider, and it turned out triaging real alerts against real attackers was exactly the deep end I'd been chasing. But the more intrusions I investigated, the more I wanted to be on the other side of them — not just reading the logs an attacker left behind, but understanding the decisions that led there. So I started building my own Active Directory attack labs on nights and weekends, chasing that same feeling I had back on the workbench — taking something apart until I actually understood it, not just until it worked again.
- 7+Years in IT overall
- 20+Client tenants covered
- 2Certs in progress — OSCP & CRTP
02 Resume
Experience
SOC Analyst
Northern Technologies Group (NTG) — Managed Security Service Provider
- Authored and drove adoption of a BloodHound CE / AzureHound CE Quarterly Identity Attack Path Review program across 20+ client tenants — cut the monthly privileged-account audit review from a full week to a single day.
- Built custom KQL detection rules in Microsoft Sentinel mapped to MITRE ATT&CK, covering credential stuffing, brute-force patterns, lateral movement, authentication bypasses/config changes, and ACL/permission abuse.
- Investigated Microsoft 365 and Entra ID abuse — privileged role misuse, delegated permission exploitation, sign-in anomalies, over-privileged accounts — across 20+ client tenants, with formal remediation guidance.
- Proposed and designed a Kasm Workspaces malware detonation sandbox, approved by SOC management, for isolated dynamic analysis of suspicious files and URLs.
- Performed static and dynamic malware analysis (FLARE VM, Ghidra, sandbox detonation) to extract IOCs, map TTPs, and produce detection logic from real samples.
- Engineered Python automation for EDR compliance gap analysis across FortiEDR and Halcyon EDR, surfacing endpoint coverage blind spots across 20+ tenants that would otherwise require manual auditing.
- Triaged and investigated alerts across a 24x7 multi-tenant SOC, consistently meeting a required minimum of 20 alerts triaged per tool, per shift, across Sentinel, Splunk, FortiEDR, Halcyon EDR, and FortiMail.
- Authored additional internal security proposals adopted by SOC management, including a centralized phishing mailbox standardizing analyst triage across all managed tenants.
Junior Technician → Senior Windows Technician
Carbondale Computer Repair
- Progressed from Junior Technician to Senior Windows Technician over two years, taking on increasing ownership of infrastructure, training, and escalated technical work.
- Administered a custom-built, in-house ticketing platform managing workflow and issue tracking for all incoming service requests.
- Configured and maintained network firewall infrastructure, managing rule sets and access policies across client and internal networks.
- Performed component-level hardware repair — soldering and board-level diagnostics — on laptops, desktops, and peripherals; trained and mentored incoming technicians.
Junior Technician
Fyxit
- Diagnosed and resolved Windows OS issues, conducted virus and malware cleanup, and performed data recovery on damaged or corrupted drives.
- Performed small electronics and mobile device repairs; managed inventory tracking and parts procurement for repair operations.
Certifications
Skills
Offensive / AD
BloodHound CE, AzureHound CE, Mimikatz, Impacket, Rubeus, CrackMapExec, PowerView, Evil-WinRM, Responder, Metasploit, Burp Suite — Kerberoasting, AS-REP Roasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, forest trust exploitation, PSRemoting backdoors
SIEM & Detection
Microsoft Sentinel (KQL — advanced), Splunk (SPL), Security Onion, FortiEDR, Halcyon EDR, FortiMail, Greenbone, Nessus, Wazuh, Zabbix
Detection Frameworks
MITRE ATT&CK, Cyber Kill Chain, Pyramid of Pain, NIST 800-61, NIST CSF, CVSS, PCI-DSS, HIPAA
Cloud / Identity
Microsoft Entra ID (Azure AD), M365 investigations, OfficeActivity log analysis, sign-in anomaly review, conditional access review, privileged role abuse investigation
Malware Analysis
FLARE VM, Ghidra, IDA Pro — static and dynamic analysis, IOC extraction, TTP mapping
Web Security
OWASP Top 10, Burp Suite, SQLMap, Nikto — application enumeration, injection, authentication bypass
Scripting
Python, PowerShell, Bash — custom tooling, API integration, automation, log enrichment
Infrastructure
Docker, Docker Compose, Vagrant, VirtualBox, pfSense, Debian Linux, systemd — lab build and hardening
Hardware / Field IT
Component-level soldering and board-level repair, PC/laptop/mobile diagnostics and rebuild, firewall configuration, ticketing system administration, data recovery
Platforms
HackTheBox (Dante Pro Lab), OffSec Proving Grounds, TryHackMe
Education
Bachelor of Science, Cybersecurity
University of Maryland Global Campus (UMGC)
Key Projects
Active Directory Attack Lab
Full attack chain practice environment — Kerberoasting, AS-REP Roasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, and forest trust exploitation — used to build MITRE ATT&CK-mapped detection logic and understand attacker dwell patterns. This is the lab behind the Attack Lab section below.
Zentrix — Pentest Productivity Tool
Python/Qt desktop app with an embedded terminal, tabbed session navigation, and a lightweight AI model that auto-generates structured notes from terminal sessions — built to cut engagement documentation overhead.
03 Badges & Certifications
Click a badge to verify it, or view it larger.
04 Attack Lab
Walk through a real attack, live.
This section will let you launch my Active Directory Attack Lab directly from the browser and follow the exact attack chain I ran — Kerberoasting, ACL/DACL abuse, Pass-the-Hash, Pass-the-Ticket, lateral movement, forest trust exploitation — with a shortcut into a read-only Splunk view of the logs it generated, plus my written analysis alongside it. No recordings, no slideshow: the actual environment, the actual telemetry.
- Launch a scoped, disposable copy of the AD Attack Lab on demand
- Desktop shortcut into Splunk showing the attack's log trail
- My write-up displayed side-by-side with the environment
05 Contact
Open to opportunities in offensive security and detection engineering.