SOCByte
Jr. Security Engineer & Engineering Team Lead
April 2026 – Present- Responded to a compromise of internet-exposed production servers running at 100% CPU, where host isolation and service termination were constrained by uptime requirements. Identified malware masquerading as Realtek audio services running from a temp directory instead of System32 by baselining process behaviour against a known-good host.
- Deployed CrowdStrike to affected hosts, validated extracted binary hashes against VirusTotal, terminated malicious services via PowerShell, and removed registry Run-key persistence. Blocked confirmed hashes and the wider threat-group IOC set sourced from Group-IB and CTM360.
- Cut active C2 communication and XMRig crypto-mining traffic with a host-based firewall using default-deny egress and an explicit allow-list of business-required ports, chosen over enabling Microsoft Defender, which would have blocked legitimate production processes. The underlying access vector was then remediated.
- Led a SIEM audit for a microfinance bank: corrected log source parsers and DSM/event mappings that were sending traffic from 50+ assets into SIM Generic, cutting unknown/unparsed events by 80% and restoring accurate normalization for rules, offenses, and reporting.
- Identified 190 unintegrated assets in the same environment and remediated their log source integrations to forward the relevant event IDs, bringing previously unmonitored systems into monitoring coverage.
- Root-caused a recurring IBM QRadar instability (an hourly, roughly one-minute service crash) to expired internal certificates; renewed the internal certificate chain, eliminating the outage window and stabilizing event collection.
- Configured the QRadar mail server and automated scheduled daily reporting to stakeholders.
- Deployed and maintained VMware ESXi infrastructure on on-premises servers, provisioning virtual machines and supporting system stability.
- Supported SOC platform operations: user management, monitoring workflows, and incident investigation and response.
SOC Analyst Trainee
February 2026 – April 2026- Investigated a quarantined email that had passed SPF/DKIM authentication and sandbox detonation and carried no links or attachments. Pivoted on sender alias, source IP, and subject line to uncover a 90-day, multi-domain campaign sending rotating proverb-based lures through an abused relay in a European datacenter; every sending IP and domain scored clean on VirusTotal.
- Identified the campaign as a reply-bait / conversation-hijack precursor (payload delivered only after a victim replies). Ran a retro-hunt sweep across the tenant, blocked the follow-on infrastructure, initiated targeted user awareness, and submitted the analysis to Trend Micro Email Security as a detection-gap report.
- Performed L1 monitoring and alert triage across SIEM/XDR/NDR platforms (Wazuh, QRadar, Rapid7 InsightIDR, Trend Micro Vision One, Vectra AI) and EDR (CrowdStrike), escalating confirmed incidents per playbooks.
- Monitored WAF events and HTTP logs for common web attacks such as SQL injection patterns, validating findings and recommending blocks.
- Operationalized threat intelligence by curating and blocking IOCs (URLs, domains, hashes) in MISP, based on Group-IB and CTM360 feeds and reports.
- Investigated active alerts by validating evidence (process and user activity, network indicators, timelines) to support accurate escalation.