End-to-End Cloud SOC Lab (Wazuh SIEM Deployment)
Architected a Cloud SOC integration lab linking AWS CloudTrail and VPC Flow Logs with Wazuh SIEM. Engineered custom detection rules (escalating critical S3 access to Level 12) and triaged simulated SSH brute-force incidents mapped to MITRE ATT&CK TTPs.
Splunk Log Analysis and Cybersecurity Monitoring Portfolio
A comprehensive portfolio demonstrating advanced skills in Splunk Enterprise, Search Processing Language (SPL), and security log analysis across multiple network protocols. This collection highlights expertise in threat hunting, anomaly detection, event classification, and SIEM workflows using real-world log data.
SOC Lab: Real-Time Threat Detection with Wazuh SIEM
This project showcases a fully functional Home Security Operations Center (SOC) built using Wazuh SIEM. The goal was to move beyond theoretical cybersecurity concepts and gain hands-on experience in threat detection, log analysis, and incident response. By simulating real-world attacks, this lab demonstrates how security teams detect and respond to malicious activities using SIEM tools.