Skip to content
View karansoni8's full-sized avatar

Block or report karansoni8

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
karansoni8/README.md

Hi, I’m Karan — SOC / SIEM Lab Builder

I’m building hands-on SOC projects focused on endpoint telemetry → SIEM detections → alert triage → incident write-ups.

Featured project

SOC Detection Lab (Elastic SIEM + Fleet + Sysmon)
Repo : https://github.com/karansoni8/soc-lab-elastic-sysmon

What I built:

  • Windows Sysmon telemetry shipped via Elastic Agent + Fleet
  • Custom detections (KQL) + alert validation
  • Triage workflow + incident report writeups
  • Troubleshooting notes (ports, services, agents)

Tech: Elastic Stack, Kibana Security, Fleet, Sysmon, Windows, Linux, KQL

LinkedIn : https://www.linkedin.com/in/karan-soni-4b56a11b4/

Pinned Loading

  1. soc-lab-elastic-sysmon soc-lab-elastic-sysmon Public

    SOC detection lab using Elastic SIEM + Fleet + Sysmon with detections, alerts, incident write-ups, and troubleshooting.

    1 1