
IT & NOC operations professional transitioning into a SOC Analyst role, with hands-on experience building and investigating a multi-layer home security lab.
UAE · Open to SOC Analyst L1 / Cybersecurity Operations opportunities
I bring 13 years of experience across enterprise IT support, NOC monitoring, identity, networking, endpoint administration, and incident ownership. I am now applying that operational foundation to cybersecurity: validating alerts, correlating evidence, defining impact, and communicating actionable next steps.
My portfolio focuses on investigation quality—not simply installing tools.
flowchart LR
A["Kali / Parrot<br/>Attack simulation"] --> B["OPNsense<br/>Firewall + Suricata"]
B --> C["Ubuntu sensor<br/>Zeek"]
B --> D["Linux endpoints<br/>Velociraptor"]
C --> E["Splunk<br/>Search + alert + dashboard"]
D --> E
| Layer | Technology | Purpose |
|---|---|---|
| Attack simulation | Kali Linux, Parrot OS | Generate controlled scans and authentication activity |
| Network control | OPNsense, Suricata | Firewall policy, traffic visibility, IDS/IPS alerts |
| Network detection | Zeek | Connection, DNS, host, and protocol telemetry |
| Endpoint visibility | Velociraptor | Artifact collection, endpoint queries, and hunts |
| SIEM | Splunk | Centralized ingestion, correlation, searches, alerts, and dashboards |
| Target systems | Ubuntu, Metasploitable 2 | Generate realistic host and service evidence |
Objective: Identify repeated SSH authentication failures and determine whether they resulted in compromise.
What I did
index=* "Failed password"
| rex field=_raw "from (?<src_ip>\d{1,3}(?:\.\d{1,3}){3})"
| where isnotnull(src_ip)
| bin _time span=5m
| stats count as failed_events values(user) as targeted_users by _time src_ip host
| where failed_events >= 5
| sort -_time
Investigation decision: Escalate when failures are followed by a successful login, a privileged account is targeted, the source appears malicious, or related lateral movement is present.
Analyzed one-password-to-many-accounts behavior, compared it with brute force, and identified the aggregation fields required to detect broad account targeting without over-alerting on ordinary user mistakes.
Built Zeek from source on ARM Ubuntu, captured traffic from the lab network, validated conn.log and dns.log, and designed the forwarding path into Splunk for network-led investigations.
Deployed a Velociraptor server and ARM clients, confirmed endpoint services and check-ins, and explored artifact collection for Linux authentication and host evidence.
flowchart LR
A["Detect<br/>Alert or anomaly"] --> B["Validate<br/>Confirm evidence"]
B --> C["Scope<br/>User, host, time, impact"]
C --> D["Respond<br/>Contain or escalate"]
D --> E["Improve<br/>Document + tune"]
cybersecurity-portfolio/
├── README.md # GitHub portfolio
└── dist/ # GitHub Pages-ready website
├── index.html
├── styles.css
├── script.js
└── assets/
└── cyber-defense-hero.png
/dist website automatically after each push to main.This portfolio documents controlled lab activity performed for defensive learning. No testing is conducted against systems without authorization.