I bring eight years of Tier 1 and Tier 2 technical-support experience troubleshooting Windows systems, internet connectivity, routers, email, TCP/IP, and DNS. I am building on that experience through hands-on cybersecurity investigations focused on alert analysis, network traffic, authentication activity, phishing, Windows logs, and SIEM tools.
I completed the Google Cybersecurity Professional Certificate, 12 cybersecurity foundation projects, 5 SOC case files, and 3 Blue Team Labs Online investigations.
Currently seeking Junior SOC Analyst, SOC Analyst I, Cybersecurity Analyst, and security-focused IT Support opportunities.
Used Azure Data Explorer and KQL to analyze failed and successful authentications, correlate source IP addresses, build a login timeline, and identify behavior consistent with password spraying.
Analyzed Windows authentication logs to identify brute-force activity, review relevant Event IDs, determine the affected account, and document the investigation.
Examined sender details, email headers, URLs, attachments, and indicators of compromise to determine whether a reported message was malicious.
Analyzed packet captures, DNS requests, protocols, and TCP streams using a structured SOC investigation and documentation process.
Worked through a structured incident-response scenario involving investigation, evidence review, containment decisions, documentation, and escalation.
- BTLO-01 — The Report — Reviewed a suspicious report, investigated the available evidence, and documented the findings.
- BTLO-02 — Phishing Analysis — Analyzed email artifacts and indicators to determine whether the message was malicious.
- BTLO-03 — Bruteforce — Investigated repeated authentication failures and supporting Windows log evidence.
- Investigating Network Traffic with Wireshark
- DNS Analysis
- Windows Failed Logon Investigation
- Phishing Email Investigation
- Suspicious Authentication Activity Using KQL
| Area | Skills and Tools |
|---|---|
| Security Operations | Alert triage, log analysis, threat hunting, IOC identification, incident response, escalation, security documentation |
| SIEM and Log Platforms | Splunk, Microsoft Sentinel, Azure Data Explorer |
| Investigation Tools | Wireshark, Windows Event Viewer, Microsoft Defender fundamentals |
| Query Languages | Kusto Query Language (KQL), Splunk Processing Language (SPL) |
| Systems | Windows, Linux, PowerShell |
| Networking | TCP/IP, DNS, DHCP, HTTP/HTTPS, ICMP |
| Frameworks | MITRE ATT&CK, NIST incident-response fundamentals |
Completed 12 structured projects covering:
- Ubuntu SOC lab setup and Linux fundamentals
- Linux log analysis, users, and permissions
- Windows Event Viewer analysis
- PowerShell fundamentals for SOC analysts
- Splunk installation, data onboarding, SPL searches, investigations, dashboards, and alerts
- SOC incident-response documentation
My next portfolio investigations focus on:
- Vulnerability management and remediation prioritization
- Endpoint and malware alert triage
- Full incident-response workflow
- Continued interview preparation and technical practice
- Google Cybersecurity Professional Certificate
Thank you for reviewing my portfolio.