Hands-on experience in security monitoring, log analysis, SIEM operations, and threat detection. I build labs, write detections, and investigate real attack patterns — not just theory.
I am a Bachelor of Computer Science graduate with hands-on experience in Security Monitoring, Log Analysis, Threat Detection, Incident Investigation, and SIEM technologies.
I have built and configured cybersecurity labs, analyzed Windows Security Logs, investigated authentication events, and worked with Splunk for security monitoring and incident detection.
I operate with a defender's mindset — I think in terms of attacker techniques, detection gaps, and incident timelines. My approach is always practical, lab-driven, and documentation-focused.
Beyond technical skills, I am the Founder of SoulMatrix, a cybersecurity startup with a vision to bring AI-powered security solution.
Built a Splunk-based lab to monitor Windows Security Logs, detect brute force attacks, investigate suspicious login activity, and create SPL-based detections for authentication anomalies.
Performed detailed analysis of Windows Security Events — successful logins, failed logins, RDP access, and privilege escalation events — to identify suspicious activity and document findings.
Created a personal SOC lab using Windows systems, Splunk, and security monitoring tools to simulate real-world monitoring and incident detection workflows end-to-end.
Conducted vulnerability assessments and documented findings, risk ratings, affected assets, and remediation recommendations in a structured professional report.
Studied and practiced TCP/IP, OSI Model, MAC Addressing, Ethernet Communication, Switching, and Security Monitoring across a virtualized lab environment.
Building an AI-powered threat hunting dashboard that automates detection of suspicious patterns across security logs, correlates events intelligently, and presents actionable threat intelligence to SOC analysts in real time.
Developing a dark web exposure monitoring system that scans for leaked credentials, sensitive data, and organizational exposure — providing early warning alerts and structured risk reports.
Attacker conducted automated RDP brute force from a single IP. After 15 failed attempts, a successful authentication was achieved, indicating weak credentials. Post-login privilege escalation events (4672) were detected, suggesting elevated access was gained. Incident classified as confirmed unauthorized access.
A password spray attack was identified from a single IP targeting multiple accounts with minimal attempts per account to avoid lockout detection. No successful authentications were confirmed — early detection. Classified as attempted unauthorized access — contained.
| Technique | ATT&CK ID | Tactic | Detection Method | Status |
|---|---|---|---|---|
| Brute Force | T1110 | Credential Access | Event ID 4625 — Failed logins threshold | ✓ Detected |
| Password Spraying | T1110.003 | Credential Access | Multi-account failure from single IP | ✓ Detected |
| Remote Services (RDP) | T1021.001 | Lateral Movement | Logon Type 10 — Event ID 4624 | ✓ Detected |
| Valid Accounts | T1078 | Defense Evasion | Successful login after multiple failures | ✓ Detected |
| Privilege Escalation | T1068 | Privilege Escalation | Event ID 4672 — Special Privileges | ✓ Detected |
| Network Service Discovery | T1046 | Discovery | Unusual network scanning patterns | ⟳ Learning |
4625 events over time — brute force visualization
Successful vs failed login correlation
IP-based attack source map and alerts
Full incident timeline — failure to resolution
Cybersecurity Startup · AI-Powered Security Solutions
Building AI-powered cybersecurity solutions for small and medium businesses. SoulMatrix focuses on making enterprise-grade security monitoring and threat detection accessible and affordable — with smart automation at its core.
// active_ai_projects
An advanced AI security system designed to autonomously monitor, detect, and respond to cyber threats in real time. RAW combines machine learning with SOC workflows to deliver intelligent threat analysis, automated incident handling, and proactive defense capabilities.
An intelligent AI personal assistant that understands context, assists with tasks, and adapts to user needs. NYREX comes in two powerful versions — one for everyday users and one built for enterprise-grade business use.
Smart personal assistant for everyday users — tasks, reminders, intelligent conversations, and productivity support.
Advanced version for companies — workflow automation, data insights, team integrations, and business-grade AI features.
Collection of SPL detection queries for brute force, password spray, RDP monitoring, and authentication anomaly detection.
Documented incident investigation reports from hands-on lab environments — RDP brute force, password spray, and privilege escalation cases.
Step-by-step documentation of building a personal SOC lab — Splunk configuration, forwarder setup, log collection, and monitoring workflows.
Windows Event Log reference notes — Event IDs, Logon Types, authentication analysis techniques, and investigation checklists.
Used for web application security testing — intercepting HTTP/S traffic, identifying vulnerabilities like XSS and injection flaws, and testing authentication mechanisms.
Performed packet-level network analysis — capturing live traffic, analyzing TCP/IP sessions, identifying suspicious communication patterns, and troubleshooting network issues.
Conducted network reconnaissance — port scanning, service version detection, OS fingerprinting, and identifying open attack surfaces on target systems.
Primary OS for security lab work — running penetration testing tools, configuring attack simulations, and practicing offensive techniques to better understand defensive gaps.
End-to-end SIEM experience — ingesting Windows security logs, writing SPL detection queries, building dashboards, and running security investigations.
Built and managed isolated lab environments — running Windows VMs for attack simulations, Splunk servers for log collection, and multi-machine SOC lab setups.
Open to SOC Analyst roles, cybersecurity internships, and blue team collaborations. Feel free to reach out.