Skip to content
Abdullah

Project · 2026

SOC Analyst Portfolio

A security-focused portfolio that documents alert triage, detections, investigations, and the tools built to support analysts. It presents the work in a way that is easy to scan and easy to trust.

Role

SOC Analyst

Status

live

Stack

SOC Operations, Detection Engineering, Incident Response, Threat Hunting, LetsDefend, TryHackMe

Overview

This repository documents security work from the perspective of a SOC analyst in active training. It covers alert triage, detection engineering, incident investigation, and the tools built to support each workflow. The goal is a public record that shows the reasoning behind the work, not just the outputs.

Structure

Case Writeups — LetsDefend (SOC003 through SOC013) — Thirteen documented investigations, each covering alert context, triage decisions, indicator enrichment, timeline reconstruction, and conclusions. Written to demonstrate analyst thinking and methodology, not just final verdicts. SOC335 (CVE-2024-49138) earned the ISC2 CC First Blood badge and led to an outreach from LetsDefend's Customer Success team to write a community walkthrough for the case.

SOC Alert Playbook Library — 36 Playbooks — A structured collection of response playbooks covering common SOC alert types: phishing, brute force, lateral movement, data exfiltration, malware execution, and more. Each playbook covers detection context, triage steps, escalation criteria, containment actions, and evidence collection. Built as a reference document, not a checklist.

Security Tools — The IOC Enricher and Phishing Analyzer are both documented here in the context of how they fit into a real analyst triage workflow, including the design decisions behind them and how they are actually used.

Platform Performance

LetsDefend — Ranked 25th in Pakistan. Produced the majority of the documented case writeups on this platform, working through real-world alert simulations across endpoint, network, and email security categories.

TryHackMe — Top 7% globally, Sapphire league. Active across both blue team (SOC, IR, detection) and red team (privilege escalation, web exploitation) learning paths.

SOC335 / CVE-2024-49138 — A Windows CLFS driver vulnerability used in ransomware campaigns. Earned the ISC2 CC First Blood badge on this case — one of the first analysts to complete and submit a full investigation. Subsequently received outreach from LetsDefend's Customer Success Manager to write an official community walkthrough for the case.

Current Direction

Active focus on penetration testing through PortSwigger Web Security Academy, working toward a Purple Team track. The goal is to combine detection and offensive perspectives — understanding how attacks work at the technical level to write better detections, not just to run attacks.

Outcomes

  • 13+ documented investigations with full triage reasoning, published publicly
  • 36-playbook alert library as a public resource for other analysts
  • Ranked 25th in Pakistan on LetsDefend
  • Top 7% globally on TryHackMe, Sapphire league
  • ISC2 CC First Blood badge on SOC335 (CVE-2024-49138)
  • LetsDefend CSM community writeup invitation

Outcomes

  • Ranked 25th in Pakistan on LetsDefend
  • Top 7% globally on TryHackMe, Sapphire league
  • Microsoft SC-900 First Blood badge, SOC335 (CVE-2024-49138)
  • LetsDefend CSM outreach — community writeup invitation