nikhen
Incident Response Virtuoso
1525 / 4703 XP to level 38
*Rankings computed based on core modules (33575 pts).
Joined in December, 2024
nikhen earned 6 badges
Download Your Certificate!
You've completed games and earned badges! Click on any badge below to view and download your certificate!

Balloons Over Iowa
This analyst completed the "Balloons Over Iowa" module, investigating a phishing and ransomware attack. They identified command and control connections, detected data exfiltration, analyzed Mimikatz activity, and observed shadow copy deletions, demonstrating their ability to effectively respond to and analyze cyber threats.
Issued on: Jan 02, 2025
.png)
Titan Shield
This analyst successfully investigated two highly sophisticated cyberattacks against TitanShield’s sensitive projects, demonstrating advanced investigative skills in identifying social engineering tactics, malicious file execution, and data exfiltration strategies. Using Kusto Query Language (KQL), they unraveled Moonstone Sleet's phishing campaign targeting Project Omega and Crimson Sandstorm’s romance scheme aimed at harvesting critical system and user information. This exercise reinforced skills in threat actor profiling, recognizing social engineering-based reconnaissance on social media, and assessing the broader security implications of protecting intellectual property in a high-stakes defense context.
Issued on: Jan 03, 2025

Envolve Labs
This analyst completed the "Envolve Labs" module. They demonstrated skills in using Kusto Query Language (KQL) in their investigation that included identifying phishing campaigns, analyzing command-line activities, and uncovering credential theft and data exfiltration. They also learned to cluster and attribute attacks to specific threat actors, connecting malicious domains and email addresses to threat actor behavior.
Issued on: Jan 05, 2025

HHC2024
This analyst successfully investigated a complex series of challenges in the "The Great Elf Conflict" for the 2024 SANS Holiday Hack Challenge. Leveraging Kusto Queries to guide their investigation, demonstrating skills in leveraging advanced tools and integrating threat data to uncover and understand security threats.
Issued on: Dec 27, 2024

Critical Compromise (ICS)
This analyst completed the Critical Compromise in Chicago module, demonstrating their ability to investigate a malware-based attack on a SCADA system. Through their use of Kusto Query Language (KQL), they uncovered the deployment of malicious software that disrupted the power grid. Their investigation helped identify the attack's origin and provided insights into the attackers’ methods, ultimately contributing to the restoration of normal operations and improving defenses for critical infrastructure.
Issued on: Dec 30, 2024

Virustotal Fundamentals
This analyst completed the "VirusTotal Fundamentals" module, which focused on using VirusTotal for comprehensive threat analysis. They demonstrated the ability to pivot around datasets, utilizing file hashes, domains, and IP addresses to uncover and correlate threats. This exercise reinforced their skills in leveraging VirusTotal's capabilities for detecting malicious activity and understanding the interconnections between various threat indicators.
Issued on: Dec 30, 2024
nikhen played 12 games
Level 1: Titan Shield (with Microsoft Defender XDR) 4000/4000
Level 1: Valdoria Votes 2750/2750
Level 2: Envolve Labs: With a twist! 950/950
Level 2: Critical Compromise In Chicago - ICS 2870/2870
Level 2: Turkey Bowl 2590/2590
Level 3: Balloons Over Iowa 4405/4405
Level 3: DAILY7 🌎 0/7066
Level 3: System Shutdown at Azure Crest! (Short Version) 4200/4800
Level 3: VirusTotal Fundamentals 2620/2620
Level 4: Sunlands 5900/8437
Level 4: Spooky Sweets 3290/7640
Pattern of Life
Issue Badge to nikhen
| # | Image | Badge | Description | Action |
|---|---|---|---|---|
| 1 | ![]() | Advanced Persistent Analyst | Someone who failed, got up, and tried again! | |
| 2 | ![]() | Helping Hand | This award is community-nominated! Someone in the KC7 community has recognized this user for their contributions to others! | |
| 3 | ![]() | Notre Dame Challenge | Completed the cybersecurity challenge event at Notre Dame in June 2023 | |
| 4 | ![]() | KC7 Top 10 (2023) | Awarded to top 10 KC7 players in 2023 | |
| 5 | ![]() | Cyber Challenge Series: Team Winner | This badge is issued to KC7 players who were members of a team that placed top 3 in a Blue Team Cyber Challenge event! | |
| 6 | ![]() | Super Fan | This badge is issued to any KC7 player who has completed 3 modules or more! | |
| 7 | ![]() | Most Improved | Someone who really improved over the course of a KC7 event! | |
| 8 | ![]() | Cyber Challenge Series: Winner | This badge is issued to KC7 players who placed top 3 (as an individual) in an Blue Team Cyber Challenge event! | |
| 9 | ![]() | 30 day hot steak | Awarded to a user who has answered a question for 30 days in a row. | |
| 10 | ![]() | 90 day streak | Awarded to a user who has answered a question for 90 days in a row. | |
| 11 | ![]() | Inside Encryptodera - Event Participant | Participant in the February 2024 monthly event featuring the Encryptodera module | |
| 12 | ![]() | The Teacher | Someone who really helped lift up their peers and enabled others to learn! | |
| 13 | ![]() | Bright Future | Someone who shows a lot of potential as a future cyber analyst! | |
| 14 | ![]() | Azure Crest | This analyst investigated a ransomware attack, where cost-cutting measures led to a single point of failure in their systems. This exercise highlighted the risks associated with prioritizing cost over security and reinforced skills in identifying vulnerabilities and understanding the broader implications of inadequate security measures in a healthcare context. | |
| 15 | ![]() | 2024 SANS New2Cyber CTF Participant | This badge has been awarded to those who took part in the 2024 SANS New2Cyber x KC7 Capture The Flag (CTF) challenge, which involved investigating a ransomware attack on a hospital. | |
| 16 | ![]() | 60 day streak | Awarded to a user who has answered a question for 60 days in a row. | |
| 17 | ![]() | 120 day streak | Awarded to a user who has answered a question for 120 days in a row! | |
| 18 | ![]() | Intro Master | ||
| 19 | ![]() | Wiccon25 | You've participated to the WICCON25 workshop! You've successfully uncovered the full attack chain of a zombie themed ransomware. |

.png)


















