Security Operations

Security Operations

Security Operations

My security work is centered on SOC operations, incident response, DFIR, network detection, threat hunting, and evidence-driven investigation. I focus on understanding what happened, validating the evidence, expanding scope carefully, and documenting findings in a way that supports practical response decisions.

Core focus areas

  • Incident response: triage, investigation, scope expansion, IOC enrichment, containment recommendations, and incident reporting
  • Network detection: PCAP analysis, DNS/HTTP traffic analysis, C2 beaconing, covert-channel investigation, Zeek, RITA, and Wireshark
  • Endpoint & identity telemetry: Wazuh, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration, and guided Microsoft Sentinel/Splunk work
  • DFIR & malware triage: Volatility 3, Procmon, Regshot, memory analysis, execution-chain reconstruction, and persistence analysis
  • Threat hunting: hypothesis-driven pivots across endpoint and network evidence with MITRE ATT&CK mapping where useful
  • SOC engineering mindset: telemetry validation, repeatable playbooks, evidence preservation, failure visibility, and clear operational documentation

Credentials

  • GIAC Certified Incident Handler (GCIH) — 92%
  • GIAC Security Essentials (GSEC) — 98%
  • GIAC Foundational Cybersecurity Technologies (GFACT)
  • SANS Technology Institute Applied Cybersecurity Certificate — expected November 2026
  • National Cyber League, Spring 2025 — Individual Top 6%, Team Top 1.3%

Packet-capture investigation of a covert HTTP-cookie exfiltration channel, including evidence reduction, ordered extraction, decoding, and reconstruction of stolen data.

SOC Lab: Wazuh, Sysmon & Zeek Telemetry Integration

Isolated VMware SOC lab integrating endpoint and network telemetry across Windows, Linux, Active Directory, Wazuh, Sysmon, and Zeek with validation and troubleshooting evidence.

SOC Investigation: TA505 MirrorBlast Campaign

Tier 1-style packet-capture triage used to confirm malicious activity, reconstruct network behavior, identify C2 indicators, and document investigative findings.

SEC-504: Digital Forensics & Incident Response

Full-scope simulated ransomware investigation using live triage, network analysis, memory forensics, endpoint artifacts, Sigma/Hayabusa, Zeek, and RITA to reconstruct activity and expand scope.

Security + Automation

My automation work is influenced by the same security principles: preserve evidence, separate trusted configuration from external inputs, validate before acting, make failures visible, and keep consequential actions behind explicit human approval.

For agentic systems and workflow automation, browse AI & Automation.