At Clover Infotech, I monitor security alerts and investigate threats across Windows endpoints, servers, and networks using Splunk SIEM and SentinelOne.
I investigate authentication attacks, suspicious remote access, phishing and Business Email Compromise, and persistence techniques. My work also includes analyzing malicious processes, PowerShell activity, malware, and ransomware alerts.
I support SIEM use-case development and alert tuning, and follow incidents through the response cycle while maintaining SLAs.

