About
SOC Analyst (L1) with 1.8+ years of experience monitoring security alerts and performing initial triage across SIEM platforms (Wazuh SIEM, QRadar, Splunk; adaptable to Microsoft Sentinel/KQL). Skilled in validating true positives and eliminating false positives through detailed log analysis, investigating phishing, malware, credential abuse, and suspicious authentication activity, and verifying IOCs (IPs, URLs, domains, file hashes, email artifacts) using VirusTotal and Hybrid Analysis. Experienced in correlating events across endpoint, authentication, and firewall logs, mapping attacker behavior to the MITRE ATT&CK framework and Cyber Kill Chain, and monitoring endpoint alerts through EDR tooling (Endpoint Central; working knowledge of Cortex XDR and Microsoft Defender). Classifies incidents by severity and business impact and escalates critical/high-severity incidents to L2/L3 teams. Comfortable working from office in permanent shift rotations and collaborating with cross-functional teams through ticketing systems (ServiceDesk Plus) and email.
Skills & Expertise (37)
Work Experience
SOC Analyst (L1)
CYE Technology Pvt. Ltd.
Mar 2025 - Jul 2026
Monitored security alerts and events across Wazuh SIEM, QRadar, and Splunk, covering firewall, IDS/IPS, endpoint, authentication, and cloud logs. Performed initial alert triage, validating true positives and eliminating false positives through detailed log analysis. Analyzed logs from endpoints, authentication systems, and firewalls, correlating events across multiple sources using Wireshark and tcpdump for packet-level inspection. Investigated phishing emails, suspicious URLs, and malicious attachments; verified IOCs (IPs, domains, URLs, file hashes, email artifacts) using VirusTotal and Hybrid Analysis. Monitored endpoint-related alerts using Endpoint Central and performed endpoint investigations. Mapped suspicious activity to the MITRE ATT&CK framework and Cyber Kill Chain to identify malicious behavior. Investigated malware, credential abuse, and suspicious authentication activities, identifying scope and impact. Classified incidents based on severity and business impact; escalated critical/high-severity alerts to L2/L3 teams when required. Created and updated incidents/tickets in ServiceDesk Plus with clear investigation notes for shift handover. Coordinated with internal teams during incident handling and investigations, following SOC procedures and maintaining incident documentation. Supported vulnerability assessment and basic security monitoring activities.
Security Researcher
24/7.ai
Aug 2024 - Jan 2025
Researched attacker techniques โ phishing, privilege escalation, lateral movement, data exfiltration โ across web apps, APIs, and cloud infrastructure, mapped to MITRE ATT&CK. Analyzed binaries, scripts, macros, and configs statically to flag malicious logic and IOCs. Ran dynamic malware analysis in sandboxed environments to profile execution behavior, persistence, and C2 communication.
Education
B.Tech, Computer Science & Engineering (IoT) - Aditya University
- 2024 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Skills (37)
Click a skill to find developers with the same skill