Security+ certified cybersecurity professional with hands-on experience in SOC operations, SIEM (Splunk, Wazuh), and network traffic analysis using Wireshark. Proficient in Linux and Windows log analysis, incident response, and threat detection. Skilled in identifying and mitigating security incidents across network and endpoint systems.
Security and SIEM tools: Splunk, Wazuh, Wireshark, Nmap, Sysmon
Operating systems: Linux (Ubuntu, Kali), Windows
Log analysis: Windows Event IDs, Sysmon, /var/log/authlog
Scripting & Automation: PowerShell, Bash
Networking: TCP/IP, DNS, HTTP/HTTPS, packet filtering, C2 traffic analysis
Identity & Access: AD, GPO, ACLs
Security Concepts: SOC monitoring, Incident Response, Threat Intelligence, Zero Trust
Frameworks & Compliance: ISO 27001, SOC 2, MITRE ATT&CK
Cloud: AWS (IAM, S3, EC2 basics), GCP (Security Overview)
1.Splunk Project — Suspicious Login Dashboard
Tools: Splunk Enterprise, Sysmon, Windows Event Logs
Outcome: Improved detection coverage for brute-force and credential-stuffing attacks.
2.Phishing Email Analysis Lab (Linux + PowerShell)
Tools: Linux CLI, PowerShell, VirusTotal, Cuckoo Sandbox
Outcome: Developed reusable phishing analysis workflow for L1 analysts.