About Me
Aspiring SOC Analyst with 300+ hours of hands-on lab experience in alert triage, SIEM analysis, incident response, and threat hunting across simulated enterprise environments. Certified in TryHackMe SOC Level 1 and SOC Level 2, with practical depth in Splunk, Wazuh, Elastic Stack, and SOAR platforms, Tines, Shuffle, and n8n, covering correlation searches, MITRE ATT&CK mapping, detection rule development, and structured incident escalation workflows.
I investigate alerts from start to finish, from initial triage and IOC enrichment using VirusTotal, AbuseIPDB, and Shodan, through lateral movement tracing, timeline reconstruction, and containment recommendations, documenting every finding in professional incident reports aligned with SOC runbook standards.
What I'm Doing
Alert Triage & Monitoring
Real-time SIEM monitoring across Splunk, Wazuh, ELK, and Sentinel, correlating multi-source logs, prioritizing alerts by severity and business impact, separating true positives from noise, and escalating to Tier 2 with clear, investigation-ready summaries.
Incident Response
Handles the full investigation lifecycle, from alert detection through containment, IOC documentation, MITRE ATT&CK technique mapping, and timeline reconstruction, with structured incident reports aligned with SOC runbook standards and clear escalation paths to Tier 2 and Tier 3.
Threat Hunting & Investigation
Hypothesis-driven threat hunts across network, endpoint, and identity telemetry, including PCAP analysis, C2 beaconing and DNS tunneling detection, lateral movement tracing, and adversary kill-chain reconstruction across Windows and Linux environments.
SOAR & Analyst Automation
Builds and operates Tines, Shuffle, and n8n playbooks that automate repetitive analyst tasks, IOC enrichment, TheHive case creation, Slack-based escalation, and human-in-the-loop approval gates for high-risk containment actions — freeing analysts to focus on investigation over administration.