SOC Alert Triage Kit
Scores synthetic alerts and renders Markdown briefings for analyst handoff.
SOC analyst · Detection engineering · IRCybersecurity Instructor & Practitioner
Defensive open-source labs for SOC, cloud IAM, incident response, threat modeling, vulnerability management, Linux hardening, and security awareness.
Safe, local-first repositories with synthetic examples, tests, documentation, security policies, demo guides, and recruiter briefs.
Scores synthetic alerts and renders Markdown briefings for analyst handoff.
SOC analyst · Detection engineering · IRReviews local AWS IAM policy JSON for wildcard access, high-risk actions, and missing conditions.
Cloud security · IAM · AWSRuns synthetic CloudTrail detections for root activity, missing MFA, logging tampering, and S3 exposure.
Cloud SOC · SIEM logic · Teaching labNormalizes evidence events into readable UTC timelines for tickets and incident review.
Incident response · Evidence · ReportingChecks Dockerfiles and Kubernetes JSON manifests for root, privileged, hostPath, and host networking risks.
DevSecOps · Docker · KubernetesGrades short security-awareness lessons with learner-friendly answer explanations.
Cybersecurity instructor · Awareness · AssessmentTurns architecture JSON into STRIDE review questions and default mitigation prompts.
AppSec · Threat modeling · Secure designRanks vulnerabilities with CVSS, exploit maturity, exposure, asset criticality, and controls.
Vuln management · Risk · GRCAudits local Linux snapshots for root SSH, password auth, IP forwarding, and duplicate UID 0 accounts.
Linux security · Hardening · AuditFinds and redacts common sensitive-data patterns before sharing logs or reports.
Privacy · GRC · Data protectionTeaching + practice: technical depth, classroom clarity, and repeatable defensive workflows.
Higher-education teaching since 2021, secure software development instruction, curriculum design, and learner assessment.
Alert triage, CloudTrail detections, incident timelines, evidence organization, and analyst communication.
AWS IAM review, CloudTrail monitoring, container baselines, cloud controls, documentation, and remediation language.
Risk-based vulnerability prioritization, PII redaction, audit-friendly notes, and stakeholder-ready explanations.
Each project is intentionally scoped to defensive use: local synthetic fixtures, no live-target scanning, no credential collection, and no offensive automation.