About
Results-driven SOC Analyst with 2+ years of hands-on experience in monitoring, detecting, investigating, and responding to security incidents across enterprise environments. Strong expertise in Windows Security, Active Directory, Azure AD, Microsoft Sentinel, Splunk SIEM, Defender for Endpoint, SentinelOne EDR/XDR, and M365 Defender Email Security.
Skills & Expertise (12)
Work Experience
SOC Analyst
Bayer India Ltd
Jul 2023 - Present
Performed 24/7 continuous monitoring of security alerts using Splunk SIEM and EDR/XDR. Monitored endpoint, network, IDS/IPS, proxy, cloud, and email security alerts for suspicious activity. Investigated Windows security events related to logon attempts, account usage, and system activity. Reviewed Active Directory alerts for account lockouts, failed logons, and unauthorized access attempts. Identified early indicators of password spray and brute-force attacks and escalated to senior analysts. Monitored authentication logs for suspicious NTLM and Kerberos activity. Reviewed Azure AD sign-in alerts for unusual login locations and risky sign-ins. Monitored endpoint alerts from SentinelOne and Microsoft Defender for Endpoint for malware and suspicious behavior. Investigated malicious and suspicious processes using process details and basic behavioral indicators. Monitored PowerShell execution alerts and flagged suspicious script activity for further analysis. Reviewed scheduled task and service creation alerts for potential persistence attempts. Monitored network traffic alerts for abnormal connections and suspicious IP addresses. Reviewed IDS/IPS alerts for scanning, exploit attempts, and malware signatures. Monitored proxy alerts for access to malicious URLs, phishing sites, and newly registered domains. Investigated antivirus alerts related to malware detections and escalated confirmed threats. Assisted in phishing investigations using Microsoft 365 Defender Email Security. Analyzed email headers, URLs, and attachments to identify phishing and malicious emails. Reported credential harvesting and malware-based phishing attempts to senior SOC analysts.
Education
Bachelor of Engineering: Computer Science - SRM Institute of Science And Technology
- · Afghanistan