Collins Jeremiah's Work | ContraWork by Collins Jeremiah
Collins Jeremiah

Collins Jeremiah

IT Support Specialist with a cybersecurity background.

New to Contra

Collins is building their profile!

A client's website stopped serving her content and started serving a Japanese e-commerce storefront instead. She runs a coaching practice, speaks only English, and sells no physical products, so the pages had nothing to do with her business. Something had taken over the site's output. I started with the file system and the logs rather than the front end, since defacement is usually a symptom. Scanning for recently added and recently modified files turned up several that had been named to pass as part of the core installation. The code inside them was obfuscated, which is not on its own proof of anything, but combined with the timestamps and the placement it was enough to keep pulling. The files turned out to be doing two jobs: injecting the spam content, and hiding themselves from the server so nothing looked wrong from the inside. Removal was the careful part. Injected code sits alongside legitimate files and deleting broadly takes the site down with it, so I traced each added and modified file individually and restored the originals rather than clearing wholesale. Once the payload was out I closed the backdoor that allowed the initial access, then locked down file permissions so the same write path could not be used again. The site came back clean. The client recorded a thank you video afterwards, which I still have.
0
6
Cover image for SOC build & security automation
SOC build & security automation Digiss LLC I worked as a Cybersecurity Analyst at Digiss, a Lagos-based cybersecurity firm, contributing to the build-out of a security operations capability across ten security domains including identity and access management, cloud security, and data protection. A SOC is only as useful as what reaches the analyst and how quickly they can act on it, and two problems surfaced early: alerts arrived without the context needed to judge them, and response depended on an analyst manually moving between tools. I contributed to standing up a Cyber Threat Intelligence platform inside the SOC, enriching alerts so triage ran on evidence rather than guesswork threat analysis capability improved. I then designed and deployed an automated SOAR solution using The Hive and Cortex, moving case creation, enrichment, and analyst handoff out of manual steps and into defined workflows. The result was a SOC where threat intelligence fed triage directly and incident workflow ran itself, leaving analysts on judgement calls instead of ticket-shuffling.
0
14
Cover image for I run IT for TechBiz
I run IT for TechBiz Global, a Berlin-based recruitment and technology company operating with a fully distributed team. I'm the single point of contact for the infrastructure: help desk and troubleshooting across user account and permission management in Google Workspace, and Personio; onboarding and offboarding; and endpoint security across the fleet. System availability sits above 99%, monitored through Uptime Robot. On the security side I handle endpoint protection, access controls, and routine security auditing. I also manage the company's web presence hosting, security hardening, and performance optimisation.
0
15