Skip to content
View JFrancisSOC's full-sized avatar

Block or report JFrancisSOC

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
JFrancisSOC/README.md

Hi, I'm Jamaal Francis

Junior SOC Analyst Candidate | Technical Support Professional | Cybersecurity Portfolio

I bring eight years of Tier 1 and Tier 2 technical-support experience troubleshooting Windows systems, internet connectivity, routers, email, TCP/IP, and DNS. I am building on that experience through hands-on cybersecurity investigations focused on alert analysis, network traffic, authentication activity, phishing, Windows logs, and SIEM tools.

I completed the Google Cybersecurity Professional Certificate, 12 cybersecurity foundation projects, 5 SOC case files, and 3 Blue Team Labs Online investigations.

Currently seeking Junior SOC Analyst, SOC Analyst I, Cybersecurity Analyst, and security-focused IT Support opportunities.

LinkedIn · GitHub Portfolio


Featured Investigations

Used Azure Data Explorer and KQL to analyze failed and successful authentications, correlate source IP addresses, build a login timeline, and identify behavior consistent with password spraying.

Analyzed Windows authentication logs to identify brute-force activity, review relevant Event IDs, determine the affected account, and document the investigation.

Examined sender details, email headers, URLs, attachments, and indicators of compromise to determine whether a reported message was malicious.

Analyzed packet captures, DNS requests, protocols, and TCP streams using a structured SOC investigation and documentation process.

Worked through a structured incident-response scenario involving investigation, evidence review, containment decisions, documentation, and escalation.


Blue Team Labs Online Investigations


SOC Case Files

  1. Investigating Network Traffic with Wireshark
  2. DNS Analysis
  3. Windows Failed Logon Investigation
  4. Phishing Email Investigation
  5. Suspicious Authentication Activity Using KQL

Technical Skills

Area Skills and Tools
Security Operations Alert triage, log analysis, threat hunting, IOC identification, incident response, escalation, security documentation
SIEM and Log Platforms Splunk, Microsoft Sentinel, Azure Data Explorer
Investigation Tools Wireshark, Windows Event Viewer, Microsoft Defender fundamentals
Query Languages Kusto Query Language (KQL), Splunk Processing Language (SPL)
Systems Windows, Linux, PowerShell
Networking TCP/IP, DNS, DHCP, HTTP/HTTPS, ICMP
Frameworks MITRE ATT&CK, NIST incident-response fundamentals

Foundation Projects

Completed 12 structured projects covering:

  • Ubuntu SOC lab setup and Linux fundamentals
  • Linux log analysis, users, and permissions
  • Windows Event Viewer analysis
  • PowerShell fundamentals for SOC analysts
  • Splunk installation, data onboarding, SPL searches, investigations, dashboards, and alerts
  • SOC incident-response documentation

Current Development

My next portfolio investigations focus on:

  • Vulnerability management and remediation prioritization
  • Endpoint and malware alert triage
  • Full incident-response workflow
  • Continued interview preparation and technical practice

Certification

  • Google Cybersecurity Professional Certificate

Contact

Thank you for reviewing my portfolio.

Pinned Loading

  1. BTLO-02--Phishing-Analysis BTLO-02--Phishing-Analysis Public

    Completed BTLO phishing investigation covering email analysis, header analysis, IOC collection, and threat investigation.

  2. BTLO-03-Bruteforce BTLO-03-Bruteforce Public

    Completed BTLO brute force investigation analyzing Windows Security Event Logs, failed authentication attempts, Event ID 4625, and attacker source information.

  3. Case-File-03-Windows-Failed-Logon-Investigation Case-File-03-Windows-Failed-Logon-Investigation Public

    A Windows Event Viewer investigation analyzing failed and successful logon events to determine whether the activity was benign or suspicious.

  4. Case-File-04-Phishing-Email-Investigation Case-File-04-Phishing-Email-Investigation Public

    Investigated a simulated phishing email using MXToolbox, email authentication results, link analysis, and MITRE ATT&CK mapping.

  5. Case-File-05-Investigating-Suspicious-Authentication-Activity-Using-KQL Case-File-05-Investigating-Suspicious-Authentication-Activity-Using-KQL Public

  6. Project-5-Windows-Event-Viewer-Log-Analysis Project-5-Windows-Event-Viewer-Log-Analysis Public

    Learn Windows Event Viewer, analyze Windows Security logs, and investigate authentication events using Event IDs 4624, 4625, and 4634.