Security Operations Center (SOC) operator with a passion for detection engineering, threat hunting, and incident response. I build practical security labs that replicate real-world attack chains and defensive workflows.
- 🎓 Computer Engineering student at École Polytechnique de Lomé — specializing in cybersecurity
- 🔴 Blue Team Focus: SOC operations, detection engineering, SIEM correlation, threat hunting, incident response
- 🟢 Red Team Awareness: Understanding attacker tactics (MITRE ATT&CK) to build better defenses
- 🧪 Active in CTF competitions and online SOC platforms — forensics, malware analysis, log analysis
- 🛠️ Building Blue Team Fusion Lab: 3-VM environment with Wazuh, Suricata, and Active Directory (AD) for simulating realistic attack scenarios and detection workflows
- 🌱 Learning philosophy: Ship real systems, automate labs, solve detection engineering problems—not just follow tutorials
- SIEM & Log Analysis: Wazuh correlation rules, Suricata IDS signatures, multi-source event enrichment
- Detection Engineering: Writing YAML-based detection rules, alert tuning, false positive reduction
- Threat Hunting: Proactive threat searches using log aggregation, behavioral analysis, TTPs
- Incident Response: Alert triage, root cause analysis, containment workflows, forensic collection
- Windows Security: Event log analysis, Active Directory monitoring, privilege escalation detection
- Network Forensics: Packet analysis, anomaly detection, traffic profiling, protocol inspection
- SOAR & Automation: Automated response playbooks, OSINT enrichment, alert orchestration
- 6-12 months: Junior SOC Analyst role — managing alerts, investigating incidents, tuning detection rules
- 12-24 months: Detection Engineer or SOC Senior Analyst — designing SIEM workflows, threat hunting campaigns, detection logic
- 2+ years: Security Architect or Threat Intel Analyst — strategy, advanced threat hunting, MITRE ATT&CK framework expertise
| Domain | Skills |
|---|---|
| Detection | SIEM rule design, Suricata/Snort IDS tuning, YARA malware signatures, alert correlation |
| Investigation | Log analysis, event timeline reconstruction, root cause analysis, forensic data collection |
| Response | Incident classification, containment actions, remediation workflows, post-incident reporting |
| Threat Intel | MITRE ATT&CK mapping, adversary behavior analysis, TTP correlation, IoC enrichment |
| Platform Skills | Wazuh (agent deployment, rules, dashboards), Grafana (visualization), Splunk/ELK (querying) |
| Automation | Detection rule scripting, playbook development, Terraform/Ansible lab orchestration |
🛰️ NYX - SIEM Correlation Engine + SOAR
Production-ready Python SIEM correlation engine with automated incident response. Multi-source log ingestion, YAML-defined detection rules, YARA malware scanning, and Grafana dashboard for real-time alert visibility and metrics.
Why it matters for SOC roles: Demonstrates detection engineering, SOAR automation, and hands-on SIEM architecture.
Python Detection Engineering SOAR YARA Grafana Log Correlation
🛡️ DevSecOps Web Lab - Attack Simulation + Blue Team Monitoring
Fully automated infrastructure-as-code lab deploying a hardened web stack (Nginx/ModSecurity WAF, OWASP Juice Shop, MySQL) with centralized SOC monitoring (Wazuh, Suricata, Grafana/Loki). Includes realistic kill chain attack simulation for testing detections.
Why it matters for SOC roles: Showcases ability to build reproducible lab environments, deploy detection tools, and simulate adversary attacks for validation.
Terraform Ansible Wazuh Suricata Grafana/Loki Kill Chain Simulation OWASP Top 10
🖥️ Online Labs - SOC & CTF Training Portfolio
Curated hands-on training across multiple SOC platforms (HackTheBox, TryHackMe, CyberDefenders) and forensic labs. Includes walkthroughs, detection techniques, and investigation methodologies.
Why it matters for SOC roles: Demonstrates continuous learning in detection engineering, forensics, and incident investigation.
Forensic Analysis Threat Hunting Log Analysis Malware Investigation CyberDefenders
🖥️ Cyber Lab - VM Lab Orchestrator (team project)
Java desktop application for managing VirtualBox-based security labs. Provides VM grouping, timestamped analyst notes, and structured PDF reporting—designed for SOC training environments.
Java 17 SQLite VBoxManage Design Patterns
- Threat Hunting: Building queries for Wazuh/Splunk to hunt for lateral movement and persistence TTPs
- Detection Rule Writing: Expanding YAML-based detection rules covering MITRE ATT&CK tactics
- Windows Event Log Analysis: Deep dive into security event logs, Kerberos analysis, and AD attacks
- Incident Response Playbooks: Documenting IR workflows for malware, data exfiltration, and ransomware
- Advanced SIEM Features: ELK stack, Splunk SPL, detection testing frameworks
- 📅 Planned: Google Cloud Security (Coursera)
- 📅 Planned: Splunk Fundamentals
- 🎯 Goal: CompTIA Security+ or CEH (later)
- 📍 Current: Active on CyberDefenders (forensics and SOC labs)
🔍 Always analyzing. 🚨 Always ready. 📊 Always learning.