SOC / SECURITY OPERATIONS

SOC Analyst Portfolio

Evidence-backed security operations work covering Wazuh, Splunk, SIEM monitoring, alert triage, Windows telemetry, investigation and detection validation.

06Evidence areas
2×SIEM platforms
LABControlled validation
OPENSource-linked evidence

Evidence

Linked source material
01

Wazuh SIEM

Monitoring, log analysis, alert triage and investigation evidence.

WazuhSIEMAlert Triage
View evidence →
02

Splunk SOC Lab Track

Six connected labs covering authentication hunting, endpoint investigation, web attacks, SPL detection engineering, SOC monitoring and end-to-end investigation.

SplunkSPLThreat HuntingDetection
View six labs →
03

Windows + Sysmon

Endpoint telemetry, process activity and security-event analysis.

WindowsSysmonTelemetry
View evidence →
04

Flagship SOC Investigation

End-to-end investigation workflow with evidence, analysis and response decisions.

InvestigationIRATT&CK
View evidence →
05

SOC Alert Triage

Alert enrichment, IOC workflows and repeatable triage processes.

AutomationIOCTriage
View evidence →
06

SOC Evidence Map

Recruiter-oriented index connecting SOC claims to supporting repository evidence.

Evidence MapValidation
View evidence →

SIEM progression

Current → next platform
Wazuh → Splunk → Microsoft Sentinel + Microsoft Defender XDR
Microsoft Sentinel/Defender is the next planned lab track. It is not represented as completed work until the labs are genuinely executed and validated.

Evidence integrity

Scope & limitations
The portfolio distinguishes controlled laboratory validation, synthetic or offline material, and methodology/architecture work. Laboratory scenarios are not presented as production incidents or client engagements. Screenshots are retained only where genuinely captured.