Skip to content
View Ohdele's full-sized avatar

Block or report Ohdele

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Ohdele/README.md

Hi, I'm Dele

I am a Cybersecurity professional focused on Security Operations (SOC), SIEM monitoring, detection engineering, incident response, and security automation. I build hands-on cybersecurity labs that simulate real-world enterprise environments using SIEM, EDR, SOAR, threat intelligence, and adversary simulation tools. My projects demonstrate experience in log analysis, threat detection, security workflow automation, and investigation-driven security operations.

Objective

Applying skills in Security Operations, SIEM monitoring, detection engineering, incident response, security automation, and identity security. Seeking opportunities as a SOC Analyst, Security Engineer, or Incident Response Analyst to contribute to threat detection, log analysis, security investigations, and building security workflows using enterprise security tools.

Skills

Skill Associated Project
Active Directory Administration & Security AD Homelab Project
SIEM Monitoring and SOC Analysis SOC Automation with AI
Security Automation & Orchestration (SOAR) SOAR EDR Integration
SIEM Monitoring & Detection Engineering SOC ELK Detection Lab

Tools

Network

Platform

Endpoint

Framework

SIEM

API

Certifications

Projects

Deployed an Active Directory environment (DFIR.local) with a Windows Server Domain Controller and a Windows 10 client, establishing a centralized telemetry pipeline using Sysmon and Splunk Universal Forwarder into an Ubuntu-hosted Splunk SIEM instance. Simulated RDP brute-force attacks using Hydra and executed MITRE ATT&CK-based persistence techniques using Atomic Red Team to analyze Windows Event Logs (EventCode 4625/4624) and validate detection and monitoring capabilities.

Built an automated incident response pipeline using n8n to ingest Splunk SIEM alerts, enrich threat data via AbuseIPDB API, perform AI-driven risk analysis using Google Gemini, and deliver structured alerts to Slack for analyst action.

Developed a SOAR-driven incident response workflow integrating LimaCharlie EDR with Tines to automate detection ingestion, alerting (Slack/email), analyst approval flow, and endpoint isolation with post-action validation.

Built an end-to-end SOC detection and investigation lab using Elastic Stack to simulate enterprise monitoring across Windows and Linux environments. Deployed Elasticsearch, Kibana, Fleet Server, and Elastic Agent for centralized telemetry collection, integrated Windows Security logs, Sysmon, Microsoft Defender, and Linux authentication logs, and developed detection rules and dashboards for brute-force activity and adversary behavior. Implemented Mythic C2 attack simulations, mapped attacker activity to MITRE ATT&CK techniques, and integrated Elastic with osTicket for automated alert ticket creation and incident tracking workflows.

Pinned Loading

  1. AD-HOMELAB-PROJECT AD-HOMELAB-PROJECT Public

    ACTIVE DIRECTORY PROJECT

  2. kql-soc-investigations kql-soc-investigations Public

    KQL-based SOC investigation labs covering ransomware, phishing, and endpoint attacks using Azure Data Explorer. Focus on log correlation, threat hunting, and incident response analysis.

  3. soar-edr-integration soar-edr-integration Public

    SOAR and EDR integration project demonstrating automated threat detection, alerting, and response using LimaCharlie, Tines, Slack, and email, including endpoint isolation and validation workflows.

  4. SOC-Automation-AI SOC-Automation-AI Public

    Automated SOC workflow using n8n to ingest Splunk alerts, enrich IOC via AbuseIPDB, analyze threats with Gemini AI, and dispatch structured alerts to Slack.

  5. SOC-ELK-Detection-Lab SOC-ELK-Detection-Lab Public

    End-to-end SOC detection lab simulating ELK-based monitoring, log ingestion, security event detection, and incident investigation across Windows and Linux environments.

  6. ci-cd-final-project ci-cd-final-project Public

    Python