Security Operations & Network Analysis

Investigating attacks. Finding the truth in the evidence.

I investigate endpoint, network, memory, and Windows event evidence in hands-on labs and projects to reconstruct attack chains, determine scope, and document defensible findings.

Portrait of Jacob Macdonnell
Jacob MacdonnellSecurity Analyst
Security OperationsNetwork AnalysisIncident InvestigationEndpoint & Log Analysis
GCIHCertified Incident HandlerCertified · 92%
GSECSecurity EssentialsCertified · 98%
GFACTFoundational Cybersecurity TechnologiesCertified · 87%
Security OperationsNetwork AnalysisIncident InvestigationEndpoint & Log Analysis

Selected investigations & projects

A curated set of work showing how I move from raw evidence to scoped findings, defensible conclusions, and documented response actions.

View all work

Featured investigation · Network Forensics

SOC Investigation: HTTP Cookie Data Exfiltration

Reconstructed covert HTTP-cookie exfiltration from packet evidence, preserving packet order and reversing XOR/Base64 encoding with Wireshark, TShark, and Python.

EvidencePCAP · HTTP cookies
MethodWireshark · TShark · Python
OutcomeReconstructed exfiltrated data
Read full investigation

GIAC certifications.

Active certifications and scores, verifiable directly with GIAC.

Verify with GIAC
GCIHCertified Incident HandlerCertified · 92%
GSECSecurity EssentialsCertified · 98%
GFACTFoundational Cybersecurity TechnologiesCertified · 87%

What the work demonstrates

The portfolio is organized around operational security capability. Tools matter where they support evidence collection, investigation, validation, and response.

Security Operations & Incident Investigation

Alert triage, incident investigation, scope expansion, IOC enrichment, playbooks/runbooks, containment recommendations, incident reporting, MITRE ATT&CK, and PICERL in labs and course simulations.

Network Analysis & Digital Forensics Labs

Wireshark, Zeek, RITA, PCAP analysis, TCP/IP, DNS, HTTP/S, C2 beacon analysis, Volatility 3, Procmon, Regshot, and malware triage.

Endpoint, Identity & SIEM

Wazuh SIEM/XDR, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration, Sentinel/KQL labs, and Splunk/SPL labs.

Systems, Cloud & Automation

Windows Server, Ubuntu/Linux, VMware, network segmentation, AWS security labs, Python, PowerShell, SQL, Git/GitHub, log parsing, and evidence extraction.

Evidence first. Clear enough to defend.

My hands-on work spans security operations, network analysis, incident investigation, Windows/Linux infrastructure, and telemetry integration. I focus on reconstructing what happened, determining scope, validating conclusions, and documenting the reasoning clearly.

Background, skills, and education
Current programSANS Technology InstituteApplied Cybersecurity Certificate (ACS)Expected November 2026
EducationUniversity of British ColumbiaBachelor of Management (Honours), Minor in PsychologyCompleted May 2023
CompetitionNational Cyber LeagueSpring 2025Top 6% individual · Top 1.3% team
Professional profileLinkedIn