Ragini
SOC Analyst
About
Results-driven SOC Analyst with 4+ years of experience in SOC and Security monitoring, incident response, threat detection, and incident investigation. Hands-on experience with Splunk ES, Microsoft Defender for Endpoint (MDE), EDR/XDR(Sentinal One) and Microsoft 365 Defender. Skilled in investigating Windows security events and network security alerts. Strong knowledge of MITRE ATT&CK Framework, and the cyber incident response lifecycle.
Skills & Expertise (32)
Work Experience
SOC Analyst
Harman International
Feb 2022 - Present
Monitored enterprise security events using Splunk Enterprise Security (ES), Microsoft Defender for Endpoint, and Microsoft 365 Defender. Performed alert triage, incident validation, and root cause analysis based on security severity and business impact. Monitored and investigated EDR/XDR alerts using SentinelOne to identify malware, ransomware, suspicious processes, persistence, lateral movement, and endpoint security threats. Investigated Remote Desktop Protocol (RDP) alerts, including brute-force attacks, unauthorized remote logins, and suspicious remote access attempts. Investigated LSASS memory access alerts to identify credential dumping attempts using techniques such as Mimikatz. Investigated malicious process execution, suspicious PowerShell activity, encoded commands, LOLBins, and abnormal parent-child process behavior. Investigated phishing emails, malicious attachments, suspicious URLs, Business Email Compromise (BEC), and user-reported phishing incidents using Microsoft 365 Defender. Investigated Password Spray attacks by analyzing authentication logs, identifying targeted accounts, and recommending remediation actions. Investigated Kerberos authentication attacks, including Kerberoasting, Golden Ticket, Silver Ticket, and abnormal Kerberos ticket activity. Investigated NTLM authentication attacks and suspicious NTLM logon events. Investigated indicators associated with Man-in-the-Middle (MITM) attacks through authentication anomalies and network communication analysis. Investigated fileless malware attacks leveraging PowerShell, WMI, MSHTA, Rundll32, Regsvr32, and other Living-off-the-Land Binaries (LOLBins). Investigated Command and Control (C2) communication by analyzing DNS requests, outbound traffic, malicious IP addresses, suspicious domains, and beaconing behavior. Performed malware analysis by validating malicious files, hashes, domains, IP addresses, URLs, and behavioral indicators using threat intelligence platforms. Performed endpoint investigations using Microsoft Defender for Endpoint and recommended containment actions, including endpoint isolation and malware remediation. Validated Indicators of Compromise (IOCs), including file hashes, domains, IP addresses, registry keys, URLs, and suspicious processes. Correlated events from SIEM, EDR, email security, firewall, and network devices to identify complex attack patterns. Conducted threat hunting activities based on IOCs, TTPs, and MITRE ATT&CK techniques to proactively identify threats. Documented incident timelines, investigation findings, root cause analysis, containment actions, and remediation recommendations. Participated in post-incident reviews and contributed to improving detection use cases and SOC operational procedures.
Network Security Analyst
Zenser Technologies
May 2019 - Jan 2022
Monitored 24 *7 network infrastructure including routers, switches, firewalls, WAN/LAN links, and network devices to ensure high availability. Performed link monitoring and investigated link down, latency, packet loss, and bandwidth utilization issues. Monitored router and switch health, interface status, CPU, memory utilization, and port availability. Investigated firewall alerts, VPN connectivity issues, and network access-related incidents. Performed network fault monitoring and coordinated with ISP teams to resolve circuit and link failures. Analyzed network performance and identified connectivity issues impacting business services. Monitored network devices using enterprise network monitoring tools and responded to critical alerts. Created and managed incident tickets, documented troubleshooting steps, and tracked issues until resolution. Escalated critical network incidents to Level-2/Level-3 support teams as required. Coordinated with network, server, and security teams during planned maintenance and incident resolution. Prepared daily health check reports and network availability reports for management review.
Education
Bachelor of Engineering in Computer - Rajeev Gandhi College of Engineering Research & Technology
- 2017 ยท Afghanistan
Certifications
No certifications added yet
Interested in this developer?
Profile Score Breakdown
Profile Overview
Availability Details
Relocation
Open to Relocation
Skills (32)
Click a skill to find developers with the same skill