SOC Analyst | CompTIA Security+ | Blue Team | SIEM | Active Directory | IAM
I am building hands-on cybersecurity labs focused on security monitoring, log analysis, incident response, and identity/access management. My goal is to transition into an entry-level SOC Analyst, Security Analyst, IAM, or GRC-focused cybersecurity role.
- CompTIA Security+
- Currently studying: CompTIA CySA+
- Windows failed logon investigations using Event Viewer and Event ID 4625
- Linux log monitoring and SSH attack detection using auth.log
- ServiceNow incident ticketing workflows
- Active Directory labs focused on users, groups, permissions, and RBAC
- SIEM fundamentals using Splunk
Investigated failed authentication attempts using Windows Event Viewer, analyzed Event ID 4625 activity, and documented signs of repeated failed logon behavior.
Repository: https://github.com/ALottJr/windows-failed-logon-investigation
Monitored Linux authentication logs, simulated failed SSH login attempts, and identified suspicious login activity using auth.log.
Repository: https://github.com/ALottJr/linux-log-monitoring-lab
Documented an IT support incident workflow involving shared folder access troubleshooting, work notes, and resolution steps in ServiceNow.
Repository: https://github.com/ALottJr/servicenow-shared-folder-access-lab
Built an Active Directory lab focused on role-based access control, user groups, NTFS permissions, and access validation.
Repository: https://github.com/ALottJr/active-directory-rbac-lab
- Windows Event Log Analysis
- Linux Log Monitoring
- SIEM Fundamentals
- Active Directory
- Identity & Access Management
- Incident Response
- ServiceNow Ticketing
- Security Monitoring -->