Manikanta Buruboina
SOC Analyst
About
SOC Analyst with 11 months of hands-on experience in security monitoring, log analysis, alert triage, and incident validation using Splunk and Microsoft Sentinel SIEM platforms. Skilled at differentiating true security incidents from benign events through log correlation, threat intelligence lookups, and mapping attacker behavior to the Cyber Kill Chain and MITRE ATT&CK framework. Comfortable with Windows and Linux command-line operations and core TCP/IP networking fundamentals. Clear communicator with strong documentation habits, quick to learn new tools, and adaptable to rotational shift environments.
Skills & Expertise (23)
Work Experience
SOC Analyst Intern
Cybervie
Dec 2026 - May 2026
Monitor real-time security alerts using SentinelOne SIEM and identify suspicious activity by reviewing Microsoft Entra ID sign-in and audit logs. Investigate authentication anomalies, including repeated failed logins and unusual successful logins from atypical locations or devices. Analyze Windows security event IDs (4624, 4625, 4688) to determine malicious behavior and distinguish false positives from real incidents. Escalate confirmed incidents to higher-level teams with complete supporting documentation. Perform phishing email analysis, reviewing headers, sender spoofing indicators, and embedded malicious URLs. Check IP, domain, and file hash reputation using threat intelligence platforms such as VirusTotal. Correlate logs across multiple sources to reconstruct attack timelines and identify affected systems. Map attacker activity to the Cyber Kill Chain and MITRE ATT&CK framework to support triage and severity assessment. Create incident reports detailing severity, business impact, and recommended remediation steps. Investigate brute-force login attempts followed by successful account compromise and escalate for containment. Review phishing-triggered user activity to identify malicious external connections and abnormal login patterns.
SOC Analyst L1
CYE Technology Pvt Ltd
Jul 2025 - Nov 2025
Monitored security alerts and events in real time using Splunk and Microsoft Sentinel, differentiating true security incidents from benign events and policy violations. Performed log analysis and correlation across authentication, network, and endpoint sources to detect suspicious activity and reduce false positives. Conducted alert triage and initial incident validation, escalating confirmed threats to Level 2 analysts per structured SOC workflow (Detection → Analysis → Escalation → Closure). Applied the Cyber Kill Chain model to break down attacker stages — from reconnaissance through actions on objectives — to prioritize response actions. Investigated phishing emails and suspicious URLs/IPs using threat intelligence tools (VirusTotal, AbuseIPDB, URLScan) to assess indicators of compromise (IOCs). Reviewed EDR/XDR alerts (Microsoft Defender, CrowdStrike) to support threat detection and containment efforts. Documented incident findings, alert dispositions, and investigation notes to maintain accurate records for reporting and audit readiness. Applied foundational knowledge of Windows and Linux operating systems, command-line operations, and TCP/IP networking fundamentals to support investigations. Applied foundational knowledge of the MITRE ATT&CK framework and attack lifecycle to support threat classification and severity assessment.
Education
Bachelor of Science - Dr. Bhimrao Ambedkar University
- 2020 · Afghanistan
Intermediate - Narayana Junior College
- 2016 · Afghanistan
SSC - Vidyavikas High School
- 2014 · Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Visa Status
Need Sponsorship
Relocation
Depends on Offer
Skills (23)
Click a skill to find developers with the same skill