Analytical and hands-on Junior SOC Analyst / Blue Team Specialist focused on SIEM deployment, threat hunting, endpoint telemetry, network forensics, and security automation (SOAR).
Below is my operational hands-on cybersecurity portfolio built in a dedicated lab environment.
| Project | Core Stack | Description & Key Skills |
|---|---|---|
| P1: Wazuh SIEM Deployment | Wazuh, Linux, Syslog | Deployed and configured a central SIEM manager to monitor endpoints, analyze security logs, and trigger rule alerts. |
| P2: Windows Security Hardening | PowerShell, CIS Benchmarks | Automated system hardening scripts aligning Windows 11 configurations with CIS security baselines. |
| P3: Network Forensics & PCAP Analysis | Wireshark, TShark | Analyzed network traffic captures to detect DNS tunneling, unencrypted credentials, and suspicious C2 communications. |
| P4: Phishing Triage & IoC Extraction | CyberChef, MXToolbox | Conducted email header analysis, evaluated SPF/DKIM/DMARC spoofing, and extracted obfuscated IoC payloads. |
| P5: Endpoint Telemetry & Sysmon | Sysmon, Windows Events | Configured Sysmon (SwiftOnSecurity baseline) to track process creation (Event ID 1) and flag obfuscated PowerShell execution. |
| P6: Automated Threat Intel (SOAR) | VirusTotal API, PowerShell | Scripted automated REST API queries to enrich suspicious IoCs, reducing MTTD and automating Level 1 triage workflows. |
- SIEM & Monitoring: Wazuh, Elastic Stack (ELK), Windows Event Viewer, Sysmon.
- Network & Email Forensics: Wireshark, TShark, CyberChef, MXToolbox, SPF/DKIM/DMARC analysis.
- Threat Intel & Automation: VirusTotal API v3, PowerShell Scripting, REST APIs, JSON parsing.
- Frameworks & Standards: MITRE ATT&CK, CIS Benchmarks, NIST Incident Response Framework.
📬 Connect with me to discuss Blue Team operations, threat hunting, and SOC workflows!