Skip to content
View thabosakonta-wq's full-sized avatar

Block or report thabosakonta-wq

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
thabosakonta-wq/README.md

Hi, I'm Thabo Sakonta 👋

SOC Analyst | Cybersecurity Analyst | Microsoft Certified: Security Operations Analyst Associate (SC-200)

I build practical, SOC-realistic projects covering Microsoft Sentinel, Detection Engineering, Threat Hunting, DFIR, Windows security analysis, and security automation — with every project documented the way an analyst would document a real investigation.

Before cybersecurity, I spent 10+ years in the South African public sector in investigation, compliance, records management, and evidence-based documentation — a background that now underpins how I approach structured SOC monitoring, incident triage, and reporting.

🎯 Target roles: SOC Analyst · Junior SOC Analyst · Cybersecurity Analyst · Security Operations Analyst · Security Analyst


🔧 Core Skills

Security Operations: Alert Monitoring · Alert Triage · Incident Investigation · Event Correlation · Escalation Detection & Threat Hunting: Detection Engineering · Sigma · KQL · Threat Hunting · IOC Investigation · MITRE ATT&CK Microsoft Security: Microsoft Sentinel · Microsoft Defender concepts · SIEM Investigation DFIR & Endpoint: Digital Forensics & Incident Response · Endpoint Investigation · Evidence Collection · Velociraptor Automation: Python · Bash · Linux · Windows · PowerShell · Git/GitHub Network Security: Wireshark · Network Traffic Analysis · DNS · HTTP · TCP/IP Governance: POPIA Awareness · NIST Awareness · ISO 27001 Awareness


🗂️ Featured Projects

Project Focus
Microsoft Sentinel Detection Engineering Lab Sentinel, KQL, detection logic, MITRE ATT&CK, SOAR playbook
Velociraptor Investigation Lab DFIR, endpoint investigation, evidence analysis
Threat Hunting Lab Log analysis, brute-force/persistence hunting, ATT&CK mapping
Detection Engineering Lab Sigma rules for Windows security events
Python SOC Automation Lab Python log parsing, event correlation, alert analysis

🧩 Additional Projects

Supporting work demonstrating continued practical development:

Project Focus
Microsoft Sentinel Lab SOC simulation — alert triage, incident investigation
Network Traffic Analysis Lab Network monitoring, DNS/HTTP analysis, suspicious IP detection
Windows Event Analysis Lab Windows security event and authentication log analysis
Sysmon Event Analysis Lab Endpoint telemetry via Sysmon and process monitoring
MITRE ATT&CK Mapping Lab Threat mapping and detection engineering
SOC Dashboard Lab SOC dashboard development and alert metrics

📄 Certifications

  • Microsoft Certified: Security Operations Analyst Associate (SC-200) — 2026
  • Google Cybersecurity Professional Certificate — Coursera, 2025
  • Career Essentials in Cybersecurity — NEMISA, 2025
  • Cybersecurity Foundations — LinkedIn Learning, 2025
  • Career Essentials in Generative AI — NEMISA, 2025
  • Microsoft 101 & Digital Literacy — NEMISA, 2025
  • Introduction to Artificial Intelligence — LinkedIn Learning, 2025

🔗 Links

Pinned Loading

  1. Microsoft-Sentinel-Detection-Engineering-Lab Microsoft-Sentinel-Detection-Engineering-Lab Public

    Microsoft Sentinel detection engineering lab demonstrating KQL threat detection, threat hunting, MITRE ATT&CK mapping, and SOC investigation workflows.

  2. microsoft-sentinel-lab microsoft-sentinel-lab Public

    Microsoft Sentinel SOC Lab demonstrating alert triage, incident investigation, MITRE ATT&CK mapping, and threat detection workflows.

    Shell

  3. threat-hunting-lab threat-hunting-lab Public

    Hands-on threat hunting lab demonstrating log analysis, IOC investigation, incident reporting, evidence collection, and SOC analyst workflows.

    Shell

  4. Python-SOC-Automation-Lab Python-SOC-Automation-Lab Public

    Python-based SOC Automation Lab demonstrating Windows Event Log analysis, detection engineering, alert correlation, incident investigation and MITRE ATT&CK mapping.

    Python

  5. velociraptor-investigation-lab velociraptor-investigation-lab Public

    Velociraptor-inspired DFIR and endpoint investigation lab using MITRE ATT&CK techniques.

    Shell

  6. detection-engineering-lab detection-engineering-lab Public

    Detection Engineering Lab demonstrating Sigma rule development, threat detection, and MITRE ATT&CK mapping.