Aspiring SOC Analyst | Threat Detection Β· Incident Response Β· Vulnerability Management
I build and document hands-on security projects β threat hunts, DFIR investigations, and detection engineering β turning real scenarios into evidence-backed write-ups. Below is a running record of the work, from live Sentinel/MDE threat hunts to home-lab SOC builds. Each project links to a full report with the queries, evidence, and MITRE ATT&CK mapping behind it.
π LinkedIn Β· π― Currently working toward: TryHackMe SAL1 Β· Azure SC-200 Β· RHCSA
| Domain | Tools & Techniques |
|---|---|
| SIEM / Log Analysis | Microsoft Sentinel, Microsoft Defender for Endpoint (MDE), KQL |
| Threat Hunting | Hypothesis-driven hunting, IoC development, MITRE ATT&CK mapping |
| Incident Response | Chronological timeline reconstruction, containment, reporting |
| Vulnerability Management | Tenable/Nessus, remediation scripting (PowerShell, Bash) |
| Detection Engineering | Home SOC + honeynet (Azure), alert tuning |
| Scripting | PowerShell, Bash, Python |
- Threat Hunt: Unauthorized TOR Usage β MDE + KQL hunt tracing Tor download, silent install, execution, and C2 connections; full timeline and response.
KQLMDEMITRE ATT&CK - Threat Hunt: Rocky Clinic IR (in progress) β Sentinel investigation of an OpenEMR EHR breach across 8 phases.
SentinelSyslogIR
- Vulnerability Management Program Implementation β End-to-end vuln management lifecycle: scanning, prioritization, remediation.
TenablePolicy
- Home SOC + Honeynet in Azure Sentinel β Built a live honeynet, ingested logs into Sentinel, and tuned detections against real-world attack traffic.
AzureSentinelDetection Engineering - Python Keylogger + Discord Webhook β Offensive tooling built to understand exfiltration and detection from the attacker's side.
PythonRed Team
Target certifications: TryHackMe SAL1 Β· Azure SC-200 Β· RHCSA
- ποΈ Level: 8 [0x8] β HACKER
- π Completed Rooms: 47
- π₯ Badges Earned: 11
- π Rank: Top 10%
Working the SOC Level 1 path β building the core blue-team skill set (SIEM, endpoint security, phishing analysis, and threat intelligence) that maps directly to a SOC analyst role.
| Badge | Description |
|---|---|
| 30 Day Streak | Hacking for 30 days solid |
| 7 Day Streak | Achieved a 7-day hacking streak |
| 3 Day Streak | Achieved a 3-day hacking streak |
| Networking Nerd | Completed the 'Network Fundamentals' module |
| World Wide Web | Completed the 'How The Web Works' module |
| Webbed | Understands how the world wide web works |
| cat linux.txt | Competent in Linux |
| Metasploitable | Knowledge of using Metasploit |
| Project | Category | Skills | Difficulty | Date |
|---|---|---|---|---|
| Threat Hunt: TOR Usage | Threat Hunting | KQL, MDE, ATT&CK | Medium | 2026-02 |
| Rocky Clinic IR (WIP) | Incident Response | Sentinel, Syslog | Hard | 2026-02 |
| Vuln Management Program | Vuln Mgmt | Tenable, Policy | Medium | β |
| Home SOC + Honeynet | Detection Eng | Azure, Sentinel | Medium | β |
| Python Keylogger | Red Team | Python | Easy | β |