Big Billion davidogun100@gmail.com
Aspiring SOC L1 Analyst | Microsoft Defender XDR | Azure Sentinel | KQL | Incident Response Lagos, Nigeria | Open to Remote 24/7 MSSP Roles
This repository documents 7+ hands-on SOC labs covering SIEM, EDR, Phishing, Malware, Brute Force, and Incident Response.
| Lab # | Title | Tools / Focus | Link |
|---|---|---|---|
| 01 | SIEM Alerts Triage | Defender XDR Alerts | View |
| 04 | Phishing Analysis | Email Header Analysis | View |
| 05 | Malware Alert Investigation | EDR, Process Analysis | View |
| 06 | Sentinel Brute Force Lab | Azure Sentinel, KQL | View |
| 07 | Phishing Investigation | BEC, EmailEvents KQL | View |
| 08 | Data Exfiltration Investigation | Insider Threat, DLP | View |
| 09 | Phishing Investigation - Invoice | Initial Access | View |
| 10 | Malware Infection Investigation | Execution, C2 | View |
| 📘 | KQL Practice Workbook | 40+ KQL Queries for SOC | View |
SIEM / EDR: | Microsoft Defender XDR, Azure Sentinel, Splunk | Threat Hunting: | KQL - EmailEvents, DeviceNetworkEvents, DeviceProcessEvents | IR: | Alert Triage, Incident Classification, Containment, Documentation | Frameworks: | MITRE ATT&CK, NIST 800-61 |
- Investigated and contained Phishing, BEC, Malware, and Data Exfiltration incidents
- Wrote KQL queries to hunt across 1M+ log events
- Performed device isolation, user disable, and email purge for containment
- Documented all findings in professional IR reports
LinkedIn: https://www.linkedin.com/in/david-oluwatosin-233917158/