SOC-focused cybersecurity analyst with hands-on experience building and operating a Splunk-based lab environment for security monitoring, alert triage, and endpoint investigation.
I work from telemetry to decision: validating alert context, correlating Windows and Sysmon logs, identifying suspicious execution and persistence behaviors, and documenting findings in escalation-ready format. My approach emphasizes detection logic discipline, evidence-based analysis, and consistent investigation depth.
- Design and test SIEM-driven triage workflows
- Investigate Windows endpoint telemetry using structured methodology
- Develop and validate Sigma detection logic aligned to MITRE ATT&CK
- Produce clear, technical case documentation suitable for remote SOC environments
- Google Cybersecurity Certificate (Coursera)
- Cybersecurity for Everyone (Coursera)
- Profile: github.com/KuRo0x
- Repositories: github.com/KuRo0x?tab=repositories
- Contribution Calendar: github.com/KuRo0x
