Documented work,
not a tools list
Each lab is written up the way a client would receive it — scope, method, finding, impact, remediation. Everything tested runs on infrastructure I built and own; no third-party system has ever been in scope.
SIEM Deployment & SOC Detection Lab
A full Wazuh SIEM stack — manager, indexer and dashboard — built from scratch on Ubuntu with a monitored Linux endpoint enrolled, then used to build and validate three end-to-end detection scenarios covering vulnerability, malware and intrusion detection.
Web Application Security Testing
Worked through the OWASP WebGoat labs with Burp Suite in the loop, then wrote the results up the way a client would actually receive them.
Windows telemetry, next
The next iteration of the detection lab adds a Windows endpoint with Sysmon feeding the same Wazuh stack. Most of the estates I have run have been Windows-first, and that is where the detection content a real SOC depends on actually lives. Write-up will land here when it is finished rather than when it is started.
Let's talk about the hard part.
Open to SOC Analyst, Security Analyst and Blue Team roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.
Open to IT Engineer, Network Engineer and Systems Infrastructure roles. Based in Dhaka, Bangladesh, and comfortable with distributed teams across time zones — I have spent three years working daily with a head office in Japan.