I investigate alerts, correlate evidence, assess severity, and document clear closure or escalation decisions.
7 documented SOC investigations · 3 Tier 2 escalation decisions · 9 evidence/telemetry categories
Microsoft Defender for Endpoint / Defender XDR · Microsoft Sentinel · Windows · phishing · network · KQL · Sigma
Primary proof: SOC-2026-006 — EDR-to-SIEM Incident Lifecycle
Defender for Endpoint alerts → Defender XDR incident → Microsoft Sentinel + KQL → severity reassessment → analyst disposition → resolution.
Evidence: reproducible SOC investigations performed in controlled lab environments.
Velociraptor — merged upstream contribution
PR #5046 — Fix offline collector source precondition enforcement
Fixed offline collector handling of source-level preconditions and added regression coverage. Merged upstream.
osquery — open upstream contribution
PR #9119 — Fix scheduled_tasks hidden state on Windows
Corrects Windows scheduled-task hidden-state reporting and adds a regression test for hidden, disabled tasks. Open upstream PR — not merged.
Additional security projects
- Cybersecurity Private Cloud Homelab — validated native PF segmentation, routing, NAT and allow/deny behavior; Suricata and Wazuh detections passed positive and bounded negative tests.
- TShark Teamwork SOC Case Study — independent TShark network analysis with a reproducible synthetic PCAP and retained outputs for independent verification, alongside clearly separated historical TryHackMe training.
- Kali DevSecOps Baseline — collected dated Linux security-state evidence covering firewall, services and authentication, with repeatable baseline outputs retained for review.
- Security+ Crypto Lab — retained TLS handshake and certificate-analysis evidence.
Portfolio index · CV / LinkedIn evidence map
June–August 2026 · 320 hours
- Defined security-control evaluation criteria and reviewed technical evidence for encryption in transit and at rest, including HTTPS/TLS, certificate validation, HTTP-to-HTTPS redirection and HSTS.
- Assessed evidence sufficiency and distinguished observed results from unsupported conclusions; worked with Python, JSON, JSON Schema, automated tests and Markdown in a GitHub repository with tasks tracked in Linear.
- Applied evaluation criteria to technical evidence, identified evidence gaps and determined which conclusions were sufficiently supported.
Continued development: TryHackMe · Coursera
MSIT GmbH — Cybersecurity Bootcamp · Security Operations Center Analysis 2,720 instructional hours · June 3, 2025 – August 3, 2026


