I am a Cybersecurity professional focused on Security Operations (SOC), SIEM monitoring, detection engineering, incident response, and security automation. I build hands-on cybersecurity labs that simulate real-world enterprise environments using SIEM, EDR, SOAR, threat intelligence, and adversary simulation tools. My projects demonstrate experience in log analysis, threat detection, security workflow automation, and investigation-driven security operations.
Applying skills in Security Operations, SIEM monitoring, detection engineering, incident response, security automation, and identity security. Seeking opportunities as a SOC Analyst, Security Engineer, or Incident Response Analyst to contribute to threat detection, log analysis, security investigations, and building security workflows using enterprise security tools.
| Skill | Associated Project |
|---|---|
| Active Directory Administration & Security | AD Homelab Project |
| SIEM Monitoring and SOC Analysis | SOC Automation with AI |
| Security Automation & Orchestration (SOAR) | SOAR EDR Integration |
| SIEM Monitoring & Detection Engineering | SOC ELK Detection Lab |
Deployed an Active Directory environment (DFIR.local) with a Windows Server Domain Controller and a Windows 10 client, establishing a centralized telemetry pipeline using Sysmon and Splunk Universal Forwarder into an Ubuntu-hosted Splunk SIEM instance. Simulated RDP brute-force attacks using Hydra and executed MITRE ATT&CK-based persistence techniques using Atomic Red Team to analyze Windows Event Logs (EventCode 4625/4624) and validate detection and monitoring capabilities.
Built an automated incident response pipeline using n8n to ingest Splunk SIEM alerts, enrich threat data via AbuseIPDB API, perform AI-driven risk analysis using Google Gemini, and deliver structured alerts to Slack for analyst action.
Developed a SOAR-driven incident response workflow integrating LimaCharlie EDR with Tines to automate detection ingestion, alerting (Slack/email), analyst approval flow, and endpoint isolation with post-action validation.
Built an end-to-end SOC detection and investigation lab using Elastic Stack to simulate enterprise monitoring across Windows and Linux environments. Deployed Elasticsearch, Kibana, Fleet Server, and Elastic Agent for centralized telemetry collection, integrated Windows Security logs, Sysmon, Microsoft Defender, and Linux authentication logs, and developed detection rules and dashboards for brute-force activity and adversary behavior. Implemented Mythic C2 attack simulations, mapped attacker activity to MITRE ATT&CK techniques, and integrated Elastic with osTicket for automated alert ticket creation and incident tracking workflows.

