~$ robertnile

status: open to work

Robert Chimuanya Nwodu Robert Chimuanya Nwodu_

IT Security Analyst — SOC Operations & Incident Response

I build home-lab SOC environments end to end — attack simulation, log pipelines, SPL/VQL detections, and the documentation a real blue team would expect to find behind them. Based in Nigeria, working remote.

// about

From the queue to the writeup

I'm training as an IT Security Analyst, currently a SOC Analyst Trainee at Luke Tech Limited (Canada, remote) working from Nigeria. My background is self-directed: every lab on this page started as "how would I actually detect this?" and ended with a working pipeline, a set of SPL or VQL queries, and a report I'd be comfortable handing to a hiring manager.

I care about understanding why a detection works, not just copying a query that does. That means reading the protocol spec before writing the Zeek signature, and debugging the VQL aggregate function until I understand what it's actually doing under the hood.

Currently working toward CompTIA Security+ and ISC2 CC. My latest lab is a malware analysis of an AgentTesla JavaScript dropper — static analysis on REMnux, C2 extraction, and sandbox validation on Hybrid Analysis and VirusTotal.

05 home-lab projects shipped
11 attack techniques covered in DFIR lab
4 IR playbooks written, following PICERL

// case log

Investigations & lab builds

Click a ticket to expand the full case detail.

// stack

Tools & technologies

SIEM & Detection

  • Splunk
  • SPL
  • Zeek
  • Wireshark
  • Velociraptor / VQL

Offense (for understanding defense)

  • Metasploit / Metasploitable3
  • Kali Linux
  • GoPhish
  • dnscat2
  • Nmap

Frameworks & Process

  • MITRE ATT&CK
  • Incident Response Playbooks
  • PICERL Framework

Infra & Scripting

  • VirtualBox
  • Ubuntu Server
  • SQL
  • Bash

// certifications

In progress

September 2026

CompTIA Security+

Studying with Professor Messer and Jason Dion courseware.

October 2026

ISC2 Certified in Cybersecurity (CC)

Foundational security domains and entry-level governance.

// contact

Let's talk

Open to fully remote SOC / Blue Team roles. Reach out directly or find the work on GitHub.