Cyber Threat Intelligence · Threat Hunting · Dark-Web Research

Tracking threats. Hunting intrusions. Producing actionable intelligence.

I'm Joshua Berkoh, a cybersecurity professional and PhD researcher working in threat investigations, threat hunting, and dark-web intelligence research. Through scenario-based investigations and security research, I reconstruct intrusion activity, map observed tradecraft to MITRE ATT&CK, and turn raw telemetry into clear, defensible intelligence.

MITRE ATT&CK KQL OSINT IOC Pivoting Threat Hunting Python Graph Analysis

01 — Capabilities

What I do

Demonstrated competencies across the intelligence cycle collection, analysis, and reporting grounded in completed investigative and research work.

01Intel Cycle

Cyber Threat Intelligence

Collect, analyze, and report structured intelligence on threat activity, tradecraft, indicators, and investigative findings.

02KQL · ATT&CK

Threat Hunting

Hypothesis-driven hunts across endpoint and network telemetry using KQL and the ATT&CK framework.

03DFIR

Threat Investigations

End-to-end intrusion reconstruction timelines, evidence, IOCs, and defensible assessments.

04I2P · Hidden Services

Dark-Web Intelligence

Research into anonymity networks, hidden services, and privacy-preserving infrastructure.

05Analytic Methods

Intelligence Research

Structured analytic methods, source evaluation, and confidence-based judgments.

06Method

Security Research

Tooling, measurement, and methodology that extend how threats are studied.

02 — Investigations

Featured investigations

Threat-investigation case studies drawn from realistic training environments: intrusion reconstructions with timelines, IOC analysis, and MITRE ATT&CK mapping from KC7 scenarios, and dark-web intelligence work from Flare Darkroom, all written to professional intelligence-reporting standards.

CASE-2026-002 Simulated scenario KC7 Cyber Insider Threat · Active Directory Ransomware

Inside Encryptodera: An Insider Threat Scenario

A dual-track insider-threat investigation at Encryptodera Financial: a contractor's 27-day FTP exfiltration of cold-storage crypto-wallet secrets running in parallel with a hijacked-identity intrusion that escalates to a domain-wide...

8Techniques
HighConfidence
Read investigation →
CASE-2026-003 Simulated scenario KC7 Cyber Critical Infrastructure · Supply Chain

Solvi Systems: A tale of Supply Chains and ICS

Triaging a complex supply-chain intrusion targeting regional energy distribution. Tracks the complete lifecycle from perimeter XSS probing and weaponized phishing documents to lateral movement and source-code exfiltration using...

8Techniques
HighConfidence
Read investigation →
View all investigations →

03 — Research

Current research — network measurement

Measuring the I2P hidden-service ecosystem

A verify-then-crawl measurement framework benchmarked against the c4i2p baseline — 1,400 eepsites crawled, 366,304 hyperlinks extracted — with the resulting hyperlink graph structurally characterized (bow-tie decomposition, power-law degree distribution, PageRank authority structure). Validation datasets released on IEEE DataPort (DOI: 10.21227/rkan-zq07); crawler source on GitHub. A longitudinal churn campaign (Study 2) and a cross-network generalization study (Study 3) extend the program.

Separately, two papers peer-reviewed and accepted: a behavioral temporal GNN framework for botnet detection (IEEE iThings 2026), and Chrono-GINE, a chronological edge-aware graph isomorphism network for self-supervised I2P network behavior modeling (IEEE Smart Data 2026).

Network Measurement Longitudinal Measurement Graph Analysis
Explore the research →
Fig.01 — Eepsite relationship graph

04 — Lab Activity

Recent intelligence activity

Currently working on

  • PhD research program on the I2P hidden-service ecosystem: completed crawler methodology validation (Study 1), an in-progress longitudinal eepsite churn measurement campaign (Study 2), and a planned cross-network generalization study (Study 3).

  • Building a public portfolio of scenario-based cyber threat investigations using KC7 Cyber materials, with emphasis on evidence analysis, KQL queries, IOC pivoting, ATT&CK mapping, and structured reporting.

  • Studying detection engineering concepts and workflows. This capability is actively developing and will only be published as rules, detections, or validation reports once the work is completed and defensible.

  • Developing public-facing investigation reports, research notes, and technical articles that document analytical reasoning, evidence collection, and security research.

Active Learning

Hands-on environments I use to continuously sharpen investigative and threat-intelligence skills.

KC7 Cyber

Threat Investigation

Scenario-based security investigations focused on querying telemetry, pivoting across evidence, identifying indicators, reconstructing attacker activity, and mapping behavior to MITRE ATT&CK.

  • KQL
  • IOC Pivoting
  • Threat Hunting
  • ATT&CK
  • Incident Investigation

Darkroom by Flare

Dark-Web Intelligence

Hands-on threat-intelligence training focused on underground ecosystems, compromised credentials, ransomware activity, threat-actor tradecraft, attribution, and pre-breach intelligence.

  • Dark-Web Intelligence
  • Threat Actors
  • Attribution
  • Ransomware
  • Credentials
  • Pre-Breach Intelligence
Joshua Berkoh

Joshua Berkoh — Researcher & threat investigator

05 — About

Researcher & threat investigator

I'm a PhD researcher in Information Technology and a practicing security professional. My work sits where intelligence analysis meets hands-on investigation: reconstructing intrusions, hunting suspicious activity in telemetry, and researching the infrastructure that threats rely on.

I write every investigation to be defensible evidence-first, mapped to MITRE ATT&CK, and honest about confidence. Detection engineering is an area I'm actively studying and will publish as the work matures.

SOC AnalystFinancial sector · 2021–22
Security Engineer InternIntuit · 2023
Bug-Bounty Hall of FameMultiple programs
PhD ResearcherInformation Tech · 2024–
More about me →

06 — Contact

Open to threat intelligence and research work

If your team works in cyber threat intelligence, threat hunting, security research, or network measurement, I'd welcome a conversation.