Skip to content

Repository files navigation

Big Billion davidogun100@gmail.com

SOC-BlueTeam-Lab 🛡️

Aspiring SOC L1 Analyst | Microsoft Defender XDR | Azure Sentinel | KQL | Incident Response Lagos, Nigeria | Open to Remote 24/7 MSSP Roles

This repository documents 7+ hands-on SOC labs covering SIEM, EDR, Phishing, Malware, Brute Force, and Incident Response.

📁 Lab Portfolio

Lab # Title Tools / Focus Link
01 SIEM Alerts Triage Defender XDR Alerts View
04 Phishing Analysis Email Header Analysis View
05 Malware Alert Investigation EDR, Process Analysis View
06 Sentinel Brute Force Lab Azure Sentinel, KQL View
07 Phishing Investigation BEC, EmailEvents KQL View
08 Data Exfiltration Investigation Insider Threat, DLP View
09 Phishing Investigation - Invoice Initial Access View
10 Malware Infection Investigation Execution, C2 View
📘 KQL Practice Workbook 40+ KQL Queries for SOC View

🛠️ Technical Skills

SIEM / EDR: | Microsoft Defender XDR, Azure Sentinel, Splunk | Threat Hunting: | KQL - EmailEvents, DeviceNetworkEvents, DeviceProcessEvents | IR: | Alert Triage, Incident Classification, Containment, Documentation | Frameworks: | MITRE ATT&CK, NIST 800-61 |

📊 Key Achievements

  1. Investigated and contained Phishing, BEC, Malware, and Data Exfiltration incidents
  2. Wrote KQL queries to hunt across 1M+ log events
  3. Performed device isolation, user disable, and email purge for containment
  4. Documented all findings in professional IR reports

LinkedIn: https://www.linkedin.com/in/david-oluwatosin-233917158/

About

Home lab for SOC Analyst training. Includes detection rules, playbooks and alert analysis.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors