Information Systems graduate with hands-on SOC experience at TAHAKOM, resolving up to 15 security cases weekly through SIEM triage and MITRE ATT&CK threat hunting. CompTIA Security+ certified. I turn noisy alerts into decisions.
Four months embedded in TAHAKOM's Information Security Department — real alerts, real escalations, real adversary tradecraft.
Conducted threat intelligence analysis and dark web monitoring to identify emerging threats, leaked credentials, and fresh IOCs targeting the organization — feeding findings directly into SOC incident response workflows so exposure was actioned before it became an incident.
Scroll to travel the chain. At every stage: the MITRE ATT&CK techniques an adversary uses, with the ones I have personally triaged, hunted or analyzed highlighted. Click a highlighted technique for the detail.
One real supply-chain compromise briefed to the department, one simulated enterprise breach reconstructed from raw log data, and one firewall built from bare hardware.
A maintainer-targeted phishing campaign defeated two-factor authentication, giving the attacker publishing rights to widely-used NPM packages. Malicious code was injected downstream into 18 packages — turning a single credential compromise into a dependency-graph-wide exposure. I reconstructed the attack chain and presented it, with mitigations, to TAHAKOM's Information Security department.
Boss of the SOC is a blue-team investigation lab — I worked the V1 dataset on CyberDefenders. You are dropped into an enterprise environment indexed in Splunk after a compromise has already happened: no alert to anchor on, no starting point, no summary. Just raw logs from web servers, IDS, endpoints and firewalls, and a set of questions you can only answer by reconstructing the events yourself. I worked it the way I would work a live case: establish the sequence before forming a theory, pivot on each confirmed indicator rather than broadening the search, and trust correlation across sources over any single log.
Built on a physical FortiGate 71F rather than a virtual appliance, so every interface, cable and policy decision was real. Three interfaces, three jobs: a dedicated management port with static addressing reachable only from my own laptop, an internal port feeding an access point for client devices, and the WAN. From there I wrote the security policies and NAT that let the internal segment reach the internet, and then went the other direction — using application control and web filtering to stop specific categories from leaving the network at all, including Tor and public AI tools. That second half is the part that matters. A firewall that only decides what comes in is doing half the job; the traffic worth watching in a SOC is usually outbound.
Read the alert, pick an action, and see how I'd read it. There's no score and no wrong answer — analysts disagree, and one of these three I deliberately wouldn't call either way.
A working log-search console in your browser, over a synthetic enterprise that was actually breached. Query it yourself, or follow the six questions I worked it with.
DevTheH is a fictional company with a real problem. Three days ago an endpoint alert on a single workstation was closed as benign by whoever was on shift. Nobody has looked at it since.
You have forty-eight hours of logs from five sources and no alert to anchor on. Something did happen. The console below is real: type a query, get results. Nothing is pre-filtered and nothing is highlighted for you.
There are also two things in here that look bad and are not. Finding those matters as much as finding the intrusion.
Sources: auth · endpoint · proxy · dns · firewall. Built in the browser from a fixed seed, so every visitor investigates the same environment.
Containment first, in this order: kill the VPN session and disable the account, isolate WS-0412 from the network but leave it powered on, rotate svc_backup and every credential that account could reach, then block the two domains at the firewall. The log clearing at 14:22 means the endpoint's own record is incomplete, so the proxy and the domain controller are now the primary evidence. I would not close this without knowing how the phishing email reached her inbox, because the same message almost certainly reached other people.
Platforms and frameworks I've used on real cases, grouped by what they're actually for.
Built in a live SOC environment, not a lab simulation.
Alert triage and full incident response on 6–15 cases weekly in LogRhythm — log correlation, IOC enrichment, severity calls, and escalation with defensible write-ups.
Hypothesis-driven hunts mapping adversary TTPs to the ATT&CK matrix, surfacing behavior that never fired an alert and turning findings into escalations.
Continuous monitoring of underground sources for leaked credentials, exposed assets, and chatter — turning external signals into actionable internal IOCs.
Next-generation firewall policy design, NAT rule sets, and VLAN segmentation — building the network boundaries that shrink an attacker's blast radius.
Header forensics with SPF/DKIM/DMARC validation, URL and attachment analysis, sender infrastructure pivoting, and campaign-level IOC extraction.
Network, email, disk, and metadata forensics plus steganography analysis — reconstructing what happened, in what order, and what the attacker touched.
Riyadh-based, Information Systems graduate. I spent my internship in TAHAKOM's SOC triaging six to fifteen cases a week, and it confirmed what I suspected about myself — I would rather reconstruct an incident than theorize about one.
The habit that got me here is daily practice. I work labs most days, and the structured ones moved me furthest: Tuwaiq Academy's Digital Forensics program took me through network, disk, email and metadata forensics properly rather than in passing, and Boss of the SOC on CyberDefenders taught me to pivot on a confirmed indicator instead of widening a search and hoping. There is always something I did not know yesterday. Turning up to it every day is the only method I have found that works.
I am early in this, and I would rather say so than write like someone who is not. What I have is a real SOC on my CV, Security+, and the habit of building the timeline before forming an opinion. What I want is a team that will push me harder than I would push myself.
Based in Riyadh, working across Saudi Arabia. Email gets the fastest reply. I read everything that comes in.