π‘οΈ Cybersecurity Analyst (Blue Team) β’ SOC Operations β’ Incident Response β’ Python Automation
I am an aspiring Blue Team Cybersecurity Analyst with hands-on experience investigating security events, analyzing logs, and documenting SOC-style investigations using Splunk, Elastic Stack, Wireshark, Linux, Windows, and Python.
My passion is understanding how attackers operate and applying that knowledge to strengthen defensive security. Through practical labs and investigation-based projects, I continue building the technical skills required in modern Security Operations Centers (SOC).
- π‘οΈ Blue Team Cybersecurity Analyst
- π SOC Monitoring & Incident Response
- π Threat Detection & Log Analysis
- π Splunk & Elastic Stack Investigations
- π Network Traffic Analysis using Wireshark
- π Python Security Automation
- π§ͺ Malware Analysis & Threat Hunting Labs
- π Building Recruiter-Ready Investigation Case Studies
- π― Seeking an Entry-Level SOC Analyst Role
Issued: July 2026
Core Skills
- Threat Management
- Security Architecture
- Network Security
- Identity & Access Management
- Incident Response
- Security Operations
- Risk Management
- Cryptography
Issued: September 2025
Issued: September 2025
Issued: July 2025
Issued: June 2025
Completed: September 2025
Focus Areas
- Initial Access Techniques
- Windows Exploitation Concepts
- EternalBlue
- Privilege Escalation
- Malware Behaviour
- Network Attacks
- Password Attacks
- Web Security
- Post Exploitation Concepts
Understanding offensive techniques improves defensive detection, incident response, and threat investigation.
π§ͺ Udemy Certificate: View Certificate
Each repository documents a realistic investigation with:
β Scenario Overview
β Evidence Collection
β Log Analysis
β Detection Logic
β Analyst Reasoning
β Lessons Learned
SOC investigations covering containment, eradication, recovery, IOC analysis, and incident documentation.
Threat investigations performed using Splunk and Elastic Stack with log correlation and timeline analysis.
A collection of malware analysis case studies focused on understanding malware behavior, identifying indicators of compromise (IOCs), and documenting analyst findings.
Topics Covered
- Static Analysis
- Dynamic Analysis
- Process Investigation
- Registry Artifacts
- Persistence Mechanisms
- File System Analysis
- Windows Event Logs
- Indicators of Compromise (IOCs)
- MITRE ATT&CK Mapping
Detection-focused labs demonstrating how to identify malicious activity using logs, Sigma rules, and SIEM platforms.
Focus Areas
- Detection Logic
- Sigma Rules
- Windows Event IDs
- Log Correlation
- Alert Tuning
- Detection Validation
- Threat Hunting Concepts
Investigation of phishing campaigns through email analysis, attachment examination, IOC extraction, and defensive recommendations.
Topics Covered
- Header Analysis
- URL Analysis
- Attachment Analysis
- IOC Extraction
- Threat Intelligence Correlation
- Email Authentication Concepts
- SPF
- DKIM
- DMARC
Threat intelligence case studies documenting attacker techniques, malware campaigns, and adversary behavior using publicly available intelligence.
Topics Covered
- MITRE ATT&CK
- Threat Intelligence
- IOC Tracking
- Campaign Analysis
- Tactics, Techniques & Procedures (TTPs)
- Ransomware Trends
- Threat Actor Profiling
- Security Operations Center (SOC)
- Alert Monitoring
- Alert Triage
- Incident Response Lifecycle
- Threat Detection
- Threat Hunting Fundamentals
- Detection Engineering (Foundational)
- MITRE ATT&CK Framework
- Threat Intelligence
- IOC Identification
- Security Monitoring
- Case Documentation
- Search Processing Language (SPL)
- Log Correlation
- Timeline Analysis
- Alert Investigation
- Dashboard Navigation
- IOC Searching
- Kibana
- KQL
- Timeline Investigation
- Log Filtering
- Data Exploration
- Event Correlation
- Windows Event Logs
- Sysmon
- Linux Logs
- Authentication Logs
- Security Logs
- TCP/IP
- OSI Model
- DNS
- DHCP
- HTTP
- HTTPS
- FTP
- SSH
- SMB
- LDAP
- Kerberos
- RDP
- ICMP
- ARP
- NAT
- VLANs
- VPN Concepts
- Wireshark Packet Analysis
- TCP Stream Analysis
- Protocol Analysis
- Suspicious Traffic Identification
- DNS Investigation
- C2 Traffic Identification
- Beaconing Detection
- HTTP Analysis
- SMB Investigation
- Windows 10
- Windows 11
- Windows Server Fundamentals
- Windows Security
- Windows Event Viewer
- Registry Analysis
- Services
- Task Scheduler
- Ubuntu
- Kali Linux
- Bash Fundamentals
- Linux File Permissions
- Authentication Logs
- Process Investigation
- Basic Shell Scripting
- Active Directory Fundamentals
- Group Policy Concepts
- Least Privilege
- Role-Based Access Control (RBAC)
- Authentication
- Authorization
- Multi-Factor Authentication (MFA)
- Password Security
- Sigma Rules
- IOC Development
- MITRE ATT&CK Mapping
- Threat Hunting Concepts
- Detection Validation
- Security Monitoring
- Splunk
- Elastic Stack
- Kibana
- Wireshark
- Sysmon
- Searchsploit
- VirusTotal
- CyberChef
- Git
- GitHub
- Linux CLI
- Security Automation
- Log Parsing
- File Handling
- Regular Expressions
- Object-Oriented Programming
- JSON Processing
- CSV Processing
- Basic Automation Scripts
- Git
- GitHub
- Repository Management
- Markdown Documentation
β 146 Completed Rooms
My hands-on learning focuses on developing practical SOC analyst skills through realistic attack simulations and investigation-based exercises.
- Alert Triage
- Incident Response
- Windows Event Analysis
- Log Correlation
- Threat Detection
- Malware Analysis
- Network Traffic Investigation
- IOC Analysis
- MITRE ATT&CK Mapping
- Investigation Documentation
- Detection & Monitoring
- Incident Response
- Windows Fundamentals
- SOC Level 1
- Network Security
- Blue Team Labs
π Multiple badges earned through consistent hands-on practice.
π Profile
I use TryHackMe primarily as a hands-on training platform to build practical investigation skills and transform completed labs into recruiter-ready SOC case studies.
My primary interests are centered around Blue Team operations and building the practical skills required to protect enterprise environments.
- π‘οΈ Security Operations Center (SOC)
- π¨ Alert Triage & Incident Response
- π SIEM Monitoring & Log Analysis
- π Threat Hunting Fundamentals
- π§ Threat Intelligence
- 𧬠Malware Analysis
- π§ Phishing Investigation
- π Network Traffic Analysis
- π― Detection Engineering (Foundational)
- βοΈ Security Automation with Python
I'm continuously expanding my cybersecurity knowledge through certifications, practical labs, and portfolio projects.
β Continue building realistic SOC investigation case studies
β Expand my Detection Engineering portfolio
β Develop Python tools for Blue Team automation
β Improve advanced Splunk investigations
β Improve Elastic Stack (ELK) investigations
β Create Sigma detection rules
β Learn Microsoft Defender XDR fundamentals
β Learn Microsoft Sentinel
β Build threat hunting playbooks
IBM Cybersecurity
β
βΌ
Cisco Networking Academy
β
βΌ
CompTIA Security+ β
β
βΌ
SOC Investigation Portfolio
β
βΌ
CompTIA CySA+
β
βΌ
Detection Engineering
β
βΌ
Threat Hunting
β
βΌ
Security Operations Center Analyst
- π CompTIA CySA+
- π‘οΈ Detection Engineering
- π Advanced Splunk SPL
- π Elastic KQL
- π― Threat Hunting
- βοΈ Microsoft Sentinel
- π₯οΈ Microsoft Defender XDR
- π Python Security Automation
"The best defenders understand how attackers think."
I believe cybersecurity is learned through continuous practice, curiosity, and disciplined investigation. Every lab, detection, and documented case study strengthens my ability to identify threats, analyze evidence, and improve defensive security.
My goal is to contribute to a Security Operations Center where I can continue learning while helping protect systems through effective monitoring, investigation, and incident response.