SOC Analyst | Cybersecurity Analyst | Microsoft Certified: Security Operations Analyst Associate (SC-200)
I build practical, SOC-realistic projects covering Microsoft Sentinel, Detection Engineering, Threat Hunting, DFIR, Windows security analysis, and security automation — with every project documented the way an analyst would document a real investigation.
Before cybersecurity, I spent 10+ years in the South African public sector in investigation, compliance, records management, and evidence-based documentation — a background that now underpins how I approach structured SOC monitoring, incident triage, and reporting.
🎯 Target roles: SOC Analyst · Junior SOC Analyst · Cybersecurity Analyst · Security Operations Analyst · Security Analyst
Security Operations: Alert Monitoring · Alert Triage · Incident Investigation · Event Correlation · Escalation Detection & Threat Hunting: Detection Engineering · Sigma · KQL · Threat Hunting · IOC Investigation · MITRE ATT&CK Microsoft Security: Microsoft Sentinel · Microsoft Defender concepts · SIEM Investigation DFIR & Endpoint: Digital Forensics & Incident Response · Endpoint Investigation · Evidence Collection · Velociraptor Automation: Python · Bash · Linux · Windows · PowerShell · Git/GitHub Network Security: Wireshark · Network Traffic Analysis · DNS · HTTP · TCP/IP Governance: POPIA Awareness · NIST Awareness · ISO 27001 Awareness
| Project | Focus |
|---|---|
| Microsoft Sentinel Detection Engineering Lab | Sentinel, KQL, detection logic, MITRE ATT&CK, SOAR playbook |
| Velociraptor Investigation Lab | DFIR, endpoint investigation, evidence analysis |
| Threat Hunting Lab | Log analysis, brute-force/persistence hunting, ATT&CK mapping |
| Detection Engineering Lab | Sigma rules for Windows security events |
| Python SOC Automation Lab | Python log parsing, event correlation, alert analysis |
Supporting work demonstrating continued practical development:
| Project | Focus |
|---|---|
| Microsoft Sentinel Lab | SOC simulation — alert triage, incident investigation |
| Network Traffic Analysis Lab | Network monitoring, DNS/HTTP analysis, suspicious IP detection |
| Windows Event Analysis Lab | Windows security event and authentication log analysis |
| Sysmon Event Analysis Lab | Endpoint telemetry via Sysmon and process monitoring |
| MITRE ATT&CK Mapping Lab | Threat mapping and detection engineering |
| SOC Dashboard Lab | SOC dashboard development and alert metrics |
- Microsoft Certified: Security Operations Analyst Associate (SC-200) — 2026
- Google Cybersecurity Professional Certificate — Coursera, 2025
- Career Essentials in Cybersecurity — NEMISA, 2025
- Cybersecurity Foundations — LinkedIn Learning, 2025
- Career Essentials in Generative AI — NEMISA, 2025
- Microsoft 101 & Digital Literacy — NEMISA, 2025
- Introduction to Artificial Intelligence — LinkedIn Learning, 2025
- 🌐 Portfolio: thabosakonta-wq.github.io
- 💼 LinkedIn: thabo-sakonta-377a3748
- 📧 thabosakonta@gmail.com