SOC ANALYST · AVAILABLE FOR OPPORTUNITIES

Abhinav Kumar Jha

I build, monitor, investigate, and secure systems.

Entry-level SOC Analyst focused on SIEM operations, threat detection, alert triage, and incident response — from raw telemetry to escalation.

5,000+Events Ingested
1,000+Alerts Investigated
3Case Studies
2SIEM Platforms
01 // ABOUT

From telemetry to incident response.

I'm an aspiring SOC Analyst with hands-on experience across the full security operations pipeline — network infrastructure, SIEM deployment, detection engineering, and alert investigation.

My projects show a clear progression: I designed a segmented business network, deployed a cloud SIEM with Microsoft Sentinel, and built a multi-source Splunk monitoring lab correlating endpoint and network telemetry.

My focus isn't just tools — it's the process behind them: validating alerts, reducing false positives, correlating evidence, mapping activity to MITRE ATT&CK, and escalating confirmed threats.

SOC Investigation Flow
  • Event
  • Log Analysis
  • Detection
  • Alert
  • Triage
  • Correlation
  • Investigation
  • Classification
  • Documentation
  • Escalation / Closure
02 // TECH STACK

Tools I use to defend.

🛡️

SOC Operations

Log Analysis, Alert Triage, Incident Response, Email Security Analysis, Antivirus

📊

SIEM & Security Tools

Splunk, Microsoft Sentinel, Wireshark, Snort, Osquery, Sysmon

🔍

Threat Analysis

VirusTotal, AbuseIPDB, IOC Enrichment, MISP, IPinfo, Shodan, OSINT Tools

🧭

Cyber Defence Frameworks

NIST, Cyber Kill Chain, Incident Response Lifecycle, MITRE ATT&CK

☁️

Cloud Technologies

Microsoft Azure, Log Analytics, Azure Monitor, Azure VM

🌐

Networking

TCP/IP, IP Routing, Switching, VLANs, NAT, IP Subnetting, Network Troubleshooting

💻

Programming & Scripting

Python, Bash Scripting, PowerShell Scripting, KQL, SPL

03 // CASE STUDIES

Hands-on security projects.

Three end-to-end case studies covering network design, cloud SIEM, and SOC monitoring.

CASE 01

Small Business Coffee Shop Network Design

Network Infrastructure Design and Security · Cisco Packet Tracer

CiscoVLANsDHCPSubnettingRoutingSwitching

Problem Statement

A small coffee shop needed reliable connectivity for staff, secure business devices, and public Wi-Fi — without letting guest users touch internal systems.

Objectives

  • Segment internal traffic from guest traffic
  • Centralize IP management with DHCP
  • Secure device configuration
  • Scalable architecture for future growth

Architecture

 Router
   │
 Switch (Trunk)
   ├── VLAN 10 · Admin/Internal ── POS, Admin PCs, Mgmt
   └── VLAN 20 · Guest Wi-Fi ──── AP → Customer devices
        

Implementation

  • IPv4 subnetting from 172.16.0.0/16 pool
  • VLAN 10 (Admin) & VLAN 20 (Guest) with trunk links
  • Static IPs for routers, switches, APs
  • DHCP for endpoints to eliminate config errors
  • Device hardening & secure management

Security Principle

"Do not allow every device on the network to communicate with every other device by default."

Segmentation reduced attack surface and blocked lateral movement from guest devices.

Results

  • 2 VLANs isolating trusted vs untrusted users
  • 10+ endpoints served via DHCP
  • Working inter-VLAN routing & trunking
  • Foundation for investigating network-based alerts

Skills Demonstrated

SubnettingVLAN SegmentationDHCPRouting/SwitchingNetwork SecurityTroubleshooting
CASE 02

Security Threat Detection via Cloud SIEM

Microsoft Sentinel · Azure Log Analytics · KQL · MITRE ATT&CK

AzureSentinelKQLWindows LogsMITRE

Problem Statement

Simulate a real SOC pipeline where an endpoint event becomes an investigated, classified, and documented security incident.

Objectives

  • Ingest Windows Security Events into a cloud SIEM
  • Write KQL detections for brute-force & RDP abuse
  • Validate IOCs and reduce false positives
  • Map findings to MITRE ATT&CK

Architecture

 Windows Honeypot VM
        │
 Windows Security Event Logs
        │
 Azure Log Analytics Workspace
        │
 Microsoft Sentinel  ──►  KQL Detections  ──►  Analytics Rules
                                                    │
                                              SOC Investigation
        

Detection Engineering (KQL)

  • Brute Force — repeated failed logins from same source (T1110)
  • Repeated Failed Logins — abnormal auth failure volume
  • Suspicious RDP Activity — remote access anomalies
  • Account Enumeration — early-stage credential recon

Investigation Workflow

  1. Alert validation — rule, user, source IP, host, time
  2. Log analysis — auth type, status, patterns
  3. IOC validation — IPs, users, hostnames
  4. Correlation — chain multiple events
  5. False-positive reduction — legit vs malicious

Results

  • 5,000+ Windows Security Events ingested
  • Detected brute-force & suspicious RDP
  • Documented investigations per IR lifecycle
  • Findings mapped to MITRE ATT&CK T1110

Skills Demonstrated

SIEM OpsCloud SecurityKQLEvent Log AnalysisAlert TriageIOC InvestigationMITRE ATT&CKIR Documentation
CASE 03

Splunk SOC Monitoring Lab

Splunk · SPL · Sysmon · Snort · Detection Engineering

SplunkSPLSysmonSnortDashboards

Problem Statement

Build a SOC-style lab that centralizes endpoint and network telemetry, correlates events, and prioritizes alerts like a real analyst workflow.

Objectives

  • Centralize Windows + Sysmon + Snort telemetry in Splunk
  • Write SPL detections for auth & process abuse
  • Correlate endpoint and network events
  • Build dashboards & severity-based triage

Architecture

 Windows Endpoint ──► Windows Event Logs ─┐
                  └► Sysmon Telemetry ────┤
 Network         ──► Snort Alerts  ───────┤
                                          ▼
                                       Splunk
                                          │
                    SPL ─► Detections ─► Dashboards ─► Alerts ─► Investigation
        

Detection Use Cases (SPL)

  • Brute-force login attempts
  • Suspicious process activity (parent/child, cmdline)
  • Malware-related behavior indicators
  • Multi-source correlation: Windows + Sysmon + Snort

Alert Prioritization

  • Low: single failed login, no context
  • Medium: multiple failures from suspicious source
  • High: failures + success + suspicious process
  • Critical: confirmed compromise / lateral movement

Results

  • 1,000+ security events investigated
  • Integrated 3 telemetry sources
  • Custom SPL detections & dashboards
  • End-to-end triage & escalation workflow

Skills Demonstrated

SplunkSPLSysmonSnortLog CorrelationProcess InvestigationNetwork MonitoringDetection Engineering
04 // BLOGS

Articles I've written.

Sharing what I learn about SIEM, detection, and SOC operations.

MediumSIEM

Introduction to SIEM — Part 1

Foundations of Security Information and Event Management: what a SIEM does, why SOCs need it, and how logs become detections.

Read on Medium →
MediumAll Articles

More on my Medium

Follow me on Medium for upcoming write-ups on threat detection, KQL, Splunk, and incident response.

Visit Profile →
05 // CONTACT

Let's talk security.

Recruiting, collaboration, or a SOC opportunity — send a message.