At Cyberhunt IT Solution, I monitor and investigate security alerts using Splunk Enterprise Security, Microsoft Defender for Endpoint, and SentinelOne. I also investigate phishing emails with Microsoft O365 Defender.
I analyze Windows security alerts involving persistence, lateral movement, RDP, and LSASS memory access. My investigations also cover password spray attacks, Kerberoasting, suspicious NTLM events, and malicious PowerShell activity.
I investigate malware and fileless malware alerts, validate indicators of compromise, and analyze network security alerts. I follow incident response procedures to contain and resolve incidents, collaborating with security and IT teams on response and remediation.
For my Enterprise SOC: SIEM + Threat Detection & Incident Response project, I built a lab using Splunk ES, Windows, Linux, and Sysmon. I developed detection rules and practiced alert triage, log correlation, threat hunting, MITRE ATT&CK mapping, and incident response.

