Cybersecurity Analyst - SOC Operations & Threat Detection
Majdal Shams, Golan Heights, Israel
Cybersecurity analyst focused on SOC operations, threat detection, and hands-on attack simulation. I build controlled lab environments, execute real attack scenarios end-to-end, document findings, and publish everything.
CompTIA Security+ certified. ICS College SOC graduate. TryHackMe Top 2% globally. Pursuing CCNA.
Multilingual: Arabic (native), English (C1), Hebrew (working proficiency), German (A1).
A segmented multi-VM SOC lab (Kali, Ubuntu gateway, two Windows endpoints) with Wazuh SIEM, Sysmon telemetry, and centralized traffic routing; simulating real SOC network architecture. Each simulation includes full Wireshark packet analysis, Wazuh alert correlation, MITRE ATT&CK mapping, and structured investigation reports.
| Simulation | Category | Key Finding |
|---|---|---|
| Network Reconnaissance via Nmap | Reconnaissance | Wazuh and Sysmon have zero visibility into network-level scanning - IDS required |
| RDP Brute Force Attack & Detection | Credential Access | Detection is speed-dependent; NLA bypassed via NTLM fallback; full kill chain captured |
| Privilege Escalation via Always Install Elevated | Privilege Escalation | Standard user escalated to SYSTEM via GPO misconfiguration; default Wazuh config blind to the entire attack - Sysmon ingestion and FIM tuning required for detection |
Simulated attack scenario investigations using SQLite. Covers brute force authentication attacks and DNS-based data exfiltration. Each investigation includes threat intel enrichment via multi-table JOINs, beaconing detection using window functions (LAG), and a full findings report with IOCs, timeline, and recommendations.
CLI tool that parses threat reports and extracts IPs, domains, file hashes (MD5/SHA1/SHA256), emails, and CVE IDs via regex. Handles defanged IOCs automatically. Enriches indicators via AbuseIPDB, VirusTotal, and NVD. Outputs to terminal, JSON, CSV, or SQLite for persistent cross-report querying.
Ghostwave (In Development)
Open-source handheld RF signal recorder and replayer built on ESP32 + CC1101. Captures, stores, and replays 433MHz signals with a built-in display interface.
SIEM (Wazuh · Splunk · Sentinel) Threat Detection & Triage Log Analysis MITRE ATT&CK
Network Traffic Analysis Protocol Analysis (RDP · SMB · TLS) Wireshark Burp Suite
Python SQL Bash PowerShell
- CompTIA Security+ — April 2026
- SOC Analyst & Web Application Security — ICS College, 2025–2026
- TryHackMe SOC Level 1 — Top 2% globally · 100+ labs · March 2026
- CCNA — Cisco, In Progress