
roophil
Data Theft Detective
180 / 737 XP to level 29
*Rankings computed based on core modules (18405 pts).
Joined in May, 2023
roophil earned 5 badges
Download Your Certificate!
You've completed games and earned badges! Click on any badge below to view and download your certificate!

Castle & Sand
This analyst investigated an easy-level ransomware scenario by identifying adversaries' reconnaissance activities, analyzing themed phishing emails, and tracking ransomware deployment and impact. They used the Kusto Query Language (KQL) to analyze intrusion data and build an understanding of the ransomware attack lifecycle.
Issued on: Jun 11, 2023

Krusty Krab
This analyst completed the "Krusty Krab" module, investigating a phishing attack and data exfiltration. They used Kusto Query Language (KQL) to analyze email and network logs, revealing the use of deceptive email addresses and malicious domains. This exercise emphasized their ability to pivot and connect malicious domains to threat actor behavior, showcasing their proficiency in threat detection and analysis.
Issued on: Feb 27, 2025

HopsNStuff
This analyst completed the "HopsNStuff" module, investigating a cyber attack through the analysis of endpoint process events and command-line activities. They demonstrated skills in identifying anomalous file behavior by using Kusto Query Language (KQL) to uncover malicious activities. The investigation highlighted their ability to analyze and deobfuscate malicious PowerShell commands, effectively identifying and responding to data exfiltration techniques.
Issued on: Feb 27, 2025

Dai Wok Foods
This analyst completed the "Dai Wok Foods" module. They demonstrated skills in detecting phishing attempts, analyzing email logs, and using Passive DNS for domain analysis. This proficiency is vital for countering threat actor tactics and protecting organizational assets.
Issued on: Feb 27, 2025

Sunlands ☀️🚀🧑🚀
This analyst investigated a sophisticated cyber attack on the Sunlands Aeronautics and Space Administration (SASA). They demonstrated advanced skills in detecting phishing attacks, analyzing malicious file downloads, and uncovering command and control infrastructure and persistence mechanisms. This exercise showcased their ability to respond to advanced cyber threats using threat actor tactics, techniques, and procedures (TTPs).
Issued on: Feb 27, 2025
roophil played 5 games
Level 2: HopsNStuff 4460/14265
Level 2: KRUSTY KRAB 1920/7360
Level 2: Castle & Sand 8040/13050
Level 3: Dai Wok Foods 3085/11600
Level 4: Sunlands 900/8437
Pattern of Life
Issue Badge to roophil
| # | Image | Badge | Description | Action |
|---|---|---|---|---|
| 1 | ![]() | Advanced Persistent Analyst | Someone who failed, got up, and tried again! | |
| 2 | ![]() | Helping Hand | This award is community-nominated! Someone in the KC7 community has recognized this user for their contributions to others! | |
| 3 | ![]() | Notre Dame Challenge | Completed the cybersecurity challenge event at Notre Dame in June 2023 | |
| 4 | ![]() | KC7 Top 10 (2023) | Awarded to top 10 KC7 players in 2023 | |
| 5 | ![]() | Cyber Challenge Series: Team Winner | This badge is issued to KC7 players who were members of a team that placed top 3 in a Blue Team Cyber Challenge event! | |
| 6 | ![]() | Super Fan | This badge is issued to any KC7 player who has completed 3 modules or more! | |
| 7 | ![]() | Most Improved | Someone who really improved over the course of a KC7 event! | |
| 8 | ![]() | Cyber Challenge Series: Winner | This badge is issued to KC7 players who placed top 3 (as an individual) in an Blue Team Cyber Challenge event! | |
| 9 | ![]() | 30 day hot steak | Awarded to a user who has answered a question for 30 days in a row. | |
| 10 | ![]() | 90 day streak | Awarded to a user who has answered a question for 90 days in a row. | |
| 11 | ![]() | Inside Encryptodera - Event Participant | Participant in the February 2024 monthly event featuring the Encryptodera module | |
| 12 | ![]() | The Teacher | Someone who really helped lift up their peers and enabled others to learn! | |
| 13 | ![]() | Bright Future | Someone who shows a lot of potential as a future cyber analyst! | |
| 14 | ![]() | Azure Crest | This analyst investigated a ransomware attack, where cost-cutting measures led to a single point of failure in their systems. This exercise highlighted the risks associated with prioritizing cost over security and reinforced skills in identifying vulnerabilities and understanding the broader implications of inadequate security measures in a healthcare context. | |
| 15 | ![]() | 2024 SANS New2Cyber CTF Participant | This badge has been awarded to those who took part in the 2024 SANS New2Cyber x KC7 Capture The Flag (CTF) challenge, which involved investigating a ransomware attack on a hospital. | |
| 16 | ![]() | 60 day streak | Awarded to a user who has answered a question for 60 days in a row. | |
| 17 | ![]() | 120 day streak | Awarded to a user who has answered a question for 120 days in a row! | |
| 18 | ![]() | Intro Master | ||
| 19 | ![]() | Wiccon25 | You've participated to the WICCON25 workshop! You've successfully uncovered the full attack chain of a zombie themed ransomware. |

.png)


















