SOC / SIEM
Elastic SIEM Endpoint Telemetry (Sysmon)
Fleet-managed endpoint telemetry pipeline using Sysmon v15+ validated with KQL queries in Kibana Discover.
Cybersecurity projects aligned with SOC analyst and DFIR workflows.
Fleet-managed endpoint telemetry pipeline using Sysmon v15+ validated with KQL queries in Kibana Discover.
Deployed Zeek sensor and ingested DNS and connection logs into Elastic SIEM.
SPL detections and dashboards for authentication failures and suspicious activity.
Reconstructed an intrusion timeline using logs and forensic artifacts.
Processed 30,000+ indicators to support CTI enrichment workflows.
Designed and implemented an 8-bit CPU in Logisim-evolution.