Skip to content
View a-bonfim-tech's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report a-bonfim-tech

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
a-bonfim-tech/README.md

André Bonfim — SOC Analyst | Security Operations

I investigate alerts, correlate evidence, assess severity, and document clear closure or escalation decisions.

SOC Analyst Lab — Primary SOC Portfolio

View SOC Analyst Lab →

7 documented SOC investigations · 3 Tier 2 escalation decisions · 9 evidence/telemetry categories

Microsoft Defender for Endpoint / Defender XDR · Microsoft Sentinel · Windows · phishing · network · KQL · Sigma

Primary proof: SOC-2026-006 — EDR-to-SIEM Incident Lifecycle

Defender for Endpoint alerts → Defender XDR incident → Microsoft Sentinel + KQL → severity reassessment → analyst disposition → resolution.

Evidence: reproducible SOC investigations performed in controlled lab environments.

Open Source — External Validation

Velociraptor — merged upstream contribution

PR #5046 — Fix offline collector source precondition enforcement

Fixed offline collector handling of source-level preconditions and added regression coverage. Merged upstream.

osquery — open upstream contribution

PR #9119 — Fix scheduled_tasks hidden state on Windows

Corrects Windows scheduled-task hidden-state reporting and adds a regression test for hidden, disabled tasks. Open upstream PR — not merged.

Supporting Projects

Additional security projects
  • Cybersecurity Private Cloud Homelab — validated native PF segmentation, routing, NAT and allow/deny behavior; Suricata and Wazuh detections passed positive and bounded negative tests.
  • TShark Teamwork SOC Case Study — independent TShark network analysis with a reproducible synthetic PCAP and retained outputs for independent verification, alongside clearly separated historical TryHackMe training.
  • Kali DevSecOps Baseline — collected dated Linux security-state evidence covering firewall, services and authentication, with repeatable baseline outputs retained for review.
  • Security+ Crypto Lab — retained TLS handshake and certificate-analysis evidence.

Portfolio index · CV / LinkedIn evidence map

Professional Cybersecurity Experience

Panos.AI — Cybersecurity Intern

June–August 2026 · 320 hours

  • Defined security-control evaluation criteria and reviewed technical evidence for encryption in transit and at rest, including HTTPS/TLS, certificate validation, HTTP-to-HTTPS redirection and HSTS.
  • Assessed evidence sufficiency and distinguished observed results from unsupported conclusions; worked with Python, JSON, JSON Schema, automated tests and Markdown in a GitHub repository with tasks tracked in Linear.
  • Applied evaluation criteria to technical evidence, identified evidence gaps and determined which conclusions were sufficiently supported.

Contact & Continued Development

LinkedIn

Continued development: TryHackMe · Coursera

Training & Credentials

MSIT GmbH — Cybersecurity Bootcamp · Security Operations Center Analysis 2,720 instructional hours · June 3, 2025 – August 3, 2026

Pinned Loading

  1. soc-analyst-lab soc-analyst-lab Public

    SOC Tier 1 investigation portfolio with Microsoft Defender/XDR, Sentinel, phishing, Windows/network evidence, KQL, Sigma, severity reassessment and escalation/disposition.

    Python

  2. cybersecurity-private-cloud-homelab cybersecurity-private-cloud-homelab Public

    Native FreeBSD PF segmentation with Suricata/Wazuh detection evidence, synthetic test traffic and SHA-256 validated artifacts.

    Shell

  3. kali-devsecops-baseline kali-devsecops-baseline Public

    Repeatable Kali Linux workstation baseline with dated system, network, firewall and storage evidence.

    Shell