At Tata Consultancy Services, I investigate and triage approximately 40 security alerts per day across EDR and SIEM platforms. My investigations cover malware, phishing, PowerShell activity, credential attacks, ransomware indicators, and potential lateral movement.
I use Microsoft Sentinel and existing KQL queries to correlate events and build incident timelines, and I hunt for indicators across endpoint and SIEM telemetry. I also map observed activity to MITRE ATT&CK and document findings, evidence, and response actions.
In production environments, I investigate Windows and Linux security events and support containment actions such as endpoint isolation and malicious-file quarantine. In my SOC & Threat Hunting Lab, I built practical investigation scenarios and practiced incident-response workflows based on NIST SP 800-61.

