Back to Developers
Ragini

Ragini

SOC Analyst

Mumbai, India 7+ yrs exp 90 ยท Outstanding

About

Results-driven SOC Analyst with 4+ years of experience in SOC and Security monitoring, incident response, threat detection, and incident investigation. Hands-on experience with Splunk ES, Microsoft Defender for Endpoint (MDE), EDR/XDR(Sentinal One) and Microsoft 365 Defender. Skilled in investigating Windows security events and network security alerts. Strong knowledge of MITRE ATT&CK Framework, and the cyber incident response lifecycle.

Skills & Expertise (32)

Splunk Enterprise Security Advanced
8.5/10
4
Years Exp
Microsoft Defender for Endpoint Advanced
8.2/10
4
Years Exp
Cyber Kill Chain Advanced
8.0/10
4
Years Exp
MITRE ATT&CK framework Advanced
8.0/10
4
Years Exp
Sentinel One Advanced
8.0/10
4
Years Exp
Microsoft 365 Defender Advanced
8.0/10
4
Years Exp
Firewalls Advanced
7.5/10
4
Years Exp
Windows 10 Advanced
7.5/10
4
Years Exp
RDP Advanced
7.0/10
4
Years Exp
Brute Force Detection Advanced
7.0/10
4
Years Exp
Network Traffic Analysis Advanced
7.0/10
4
Years Exp
Firewall Monitoring Advanced
7.0/10
4
Years Exp
Threat Intelligence Advanced
7.0/10
4
Years Exp
IOC Analysis Advanced
7.0/10
4
Years Exp
Malware Analysis Advanced
7.0/10
4
Years Exp
Safe Attachments Advanced
7.0/10
4
Years Exp
Phishing Investigation Advanced
7.0/10
4
Years Exp
Privilege Escalation Advanced
7.0/10
4
Years Exp
Persistence Detection Advanced
7.0/10
4
Years Exp
Memory Analysis Advanced
7.0/10
4
Years Exp
PowerShell Advanced
7.0/10
4
Years Exp
Registry Monitoring Advanced
7.0/10
4
Years Exp
Windows Event Logs Advanced
7.0/10
4
Years Exp
Active Directory Advanced
7.0/10
4
Years Exp
Endpoint Security Advanced
7.0/10
4
Years Exp
Antivirus Advanced
7.0/10
4
Years Exp
IPS Advanced
7.0/10
4
Years Exp
IDS Advanced
7.0/10
4
Years Exp
Email Security Gateway Advanced
7.0/10
4
Years Exp
Proxy Servers Advanced
7.0/10
4
Years Exp
Windows Server Advanced
7.0/10
4
Years Exp
Windows 11 Advanced
7.0/10
4
Years Exp

Work Experience

SOC Analyst

Harman International

Feb 2022 - Present

Monitored enterprise security events using Splunk Enterprise Security (ES), Microsoft Defender for Endpoint, and Microsoft 365 Defender. Performed alert triage, incident validation, and root cause analysis based on security severity and business impact. Monitored and investigated EDR/XDR alerts using SentinelOne to identify malware, ransomware, suspicious processes, persistence, lateral movement, and endpoint security threats. Investigated Remote Desktop Protocol (RDP) alerts, including brute-force attacks, unauthorized remote logins, and suspicious remote access attempts. Investigated LSASS memory access alerts to identify credential dumping attempts using techniques such as Mimikatz. Investigated malicious process execution, suspicious PowerShell activity, encoded commands, LOLBins, and abnormal parent-child process behavior. Investigated phishing emails, malicious attachments, suspicious URLs, Business Email Compromise (BEC), and user-reported phishing incidents using Microsoft 365 Defender. Investigated Password Spray attacks by analyzing authentication logs, identifying targeted accounts, and recommending remediation actions. Investigated Kerberos authentication attacks, including Kerberoasting, Golden Ticket, Silver Ticket, and abnormal Kerberos ticket activity. Investigated NTLM authentication attacks and suspicious NTLM logon events. Investigated indicators associated with Man-in-the-Middle (MITM) attacks through authentication anomalies and network communication analysis. Investigated fileless malware attacks leveraging PowerShell, WMI, MSHTA, Rundll32, Regsvr32, and other Living-off-the-Land Binaries (LOLBins). Investigated Command and Control (C2) communication by analyzing DNS requests, outbound traffic, malicious IP addresses, suspicious domains, and beaconing behavior. Performed malware analysis by validating malicious files, hashes, domains, IP addresses, URLs, and behavioral indicators using threat intelligence platforms. Performed endpoint investigations using Microsoft Defender for Endpoint and recommended containment actions, including endpoint isolation and malware remediation. Validated Indicators of Compromise (IOCs), including file hashes, domains, IP addresses, registry keys, URLs, and suspicious processes. Correlated events from SIEM, EDR, email security, firewall, and network devices to identify complex attack patterns. Conducted threat hunting activities based on IOCs, TTPs, and MITRE ATT&CK techniques to proactively identify threats. Documented incident timelines, investigation findings, root cause analysis, containment actions, and remediation recommendations. Participated in post-incident reviews and contributed to improving detection use cases and SOC operational procedures.

Network Security Analyst

Zenser Technologies

May 2019 - Jan 2022

Monitored 24 *7 network infrastructure including routers, switches, firewalls, WAN/LAN links, and network devices to ensure high availability. Performed link monitoring and investigated link down, latency, packet loss, and bandwidth utilization issues. Monitored router and switch health, interface status, CPU, memory utilization, and port availability. Investigated firewall alerts, VPN connectivity issues, and network access-related incidents. Performed network fault monitoring and coordinated with ISP teams to resolve circuit and link failures. Analyzed network performance and identified connectivity issues impacting business services. Monitored network devices using enterprise network monitoring tools and responded to critical alerts. Created and managed incident tickets, documented troubleshooting steps, and tracked issues until resolution. Escalated critical network incidents to Level-2/Level-3 support teams as required. Coordinated with network, server, and security teams during planned maintenance and incident resolution. Prepared daily health check reports and network availability reports for management review.

Education

Bachelor of Engineering in Computer - Rajeev Gandhi College of Engineering Research & Technology

- 2017 ยท Afghanistan

Certifications

No certifications added yet

Interested in this developer?

Profile Score Breakdown

๐Ÿ“ท Photo 10/10
๐Ÿ“„ Resume 10/10
๐Ÿ’ผ Job Title 10/10
โœ๏ธ Bio 10/10
๐Ÿ› ๏ธ Skills 20/20
๐ŸŽ“ Education 10/10
โฑ๏ธ Experience 15/15
๐Ÿ’ฐ Rate 0/5
๐Ÿ† Certs 0/5
โœ… Verified 5/5
Total Score 90/100

Profile Overview

Member sinceJul 2026

Availability Details

Relocation

Open to Relocation