Graduate cybersecurity candidate (UK) focused on SOC Analyst roles and detection engineering fundamentals.
- Network security monitoring: Snort, tcpdump, Wireshark
- Alert triage & automation: Python log parsing, summarization
- Detection concepts: custom rules, thresholds, false-positive tuning (lab)
- Snort 3 Custom Rules: SQLi, recon/scan spikes, brute-force spikes, DoS/flooding heuristics
- Snort Fast Alert Triage (Python): parse fast alerts → JSON + SOC-style summaries