socanalyst

Farhan Fathah — Cybersecurity Portfolio

Digital cybersecurity portrait of Farhan Fathah

IT & NOC operations professional transitioning into a SOC Analyst role, with hands-on experience building and investigating a multi-layer home security lab.

UAE · Open to SOC Analyst L1 / Cybersecurity Operations opportunities

Profile

I bring 13 years of experience across enterprise IT support, NOC monitoring, identity, networking, endpoint administration, and incident ownership. I am now applying that operational foundation to cybersecurity: validating alerts, correlating evidence, defining impact, and communicating actionable next steps.

My portfolio focuses on investigation quality—not simply installing tools.

Credentials

ISC2 CC Microsoft SC-300 CEH learning CCNA networking

Home SOC lab

flowchart LR
  A["Kali / Parrot<br/>Attack simulation"] --> B["OPNsense<br/>Firewall + Suricata"]
  B --> C["Ubuntu sensor<br/>Zeek"]
  B --> D["Linux endpoints<br/>Velociraptor"]
  C --> E["Splunk<br/>Search + alert + dashboard"]
  D --> E
Layer Technology Purpose
Attack simulation Kali Linux, Parrot OS Generate controlled scans and authentication activity
Network control OPNsense, Suricata Firewall policy, traffic visibility, IDS/IPS alerts
Network detection Zeek Connection, DNS, host, and protocol telemetry
Endpoint visibility Velociraptor Artifact collection, endpoint queries, and hunts
SIEM Splunk Centralized ingestion, correlation, searches, alerts, and dashboards
Target systems Ubuntu, Metasploitable 2 Generate realistic host and service evidence

1. SSH brute-force investigation

Objective: Identify repeated SSH authentication failures and determine whether they resulted in compromise.

What I did

index=* "Failed password"
| rex field=_raw "from (?<src_ip>\d{1,3}(?:\.\d{1,3}){3})"
| where isnotnull(src_ip)
| bin _time span=5m
| stats count as failed_events values(user) as targeted_users by _time src_ip host
| where failed_events >= 5
| sort -_time

Investigation decision: Escalate when failures are followed by a successful login, a privileged account is targeted, the source appears malicious, or related lateral movement is present.

2. Password-spraying analysis

Analyzed one-password-to-many-accounts behavior, compared it with brute force, and identified the aggregation fields required to detect broad account targeting without over-alerting on ordinary user mistakes.

3. Zeek-to-Splunk network pipeline

Built Zeek from source on ARM Ubuntu, captured traffic from the lab network, validated conn.log and dns.log, and designed the forwarding path into Splunk for network-led investigations.

4. Velociraptor endpoint visibility

Deployed a Velociraptor server and ARM clients, confirmed endpoint services and check-ins, and explored artifact collection for Linux authentication and host evidence.

My investigation method

flowchart LR
  A["Detect<br/>Alert or anomaly"] --> B["Validate<br/>Confirm evidence"]
  B --> C["Scope<br/>User, host, time, impact"]
  C --> D["Respond<br/>Contain or escalate"]
  D --> E["Improve<br/>Document + tune"]
  1. Validate the alert: confirm that the event exists and the data is reliable.
  2. Establish context: identify the source, destination, user, asset, and time window.
  3. Scope the activity: search for related events before and after the trigger.
  4. Assess impact: determine whether access succeeded, privileges changed, or movement occurred.
  5. Decide and communicate: close as benign, continue monitoring, contain, or escalate with evidence.
  6. Improve detection: tune the query, add context, and record lessons learned.

Capability map

Certifications and learning

Next plans

Repository structure

cybersecurity-portfolio/
├── README.md                 # GitHub portfolio
└── dist/                     # GitHub Pages-ready website
    ├── index.html
    ├── styles.css
    ├── script.js
    └── assets/
        └── cyber-defense-hero.png

Publish on GitHub Pages

  1. Create a public GitHub repository and upload this folder.
  2. Open Settings → Pages and select GitHub Actions as the source.
  3. The included workflow publishes the /dist website automatically after each push to main.
  4. Wait for the workflow to finish, then open the GitHub Pages URL shown in the deployment.

This portfolio documents controlled lab activity performed for defensive learning. No testing is conducted against systems without authorization.