SOC Detection Engineer with hands-on experience designing and operating a self-built virtual SOC lab — covering the full detection lifecycle from raw telemetry ingestion to escalation-ready case documentation.
I work from telemetry to decision: correlating Windows Event Logs and Sysmon data, building MITRE ATT&CK-mapped Sigma rules, validating detection logic against real attacker tooling (Mimikatz, Nmap, Hydra), and producing structured investigation reports. My approach prioritises signal over noise — understanding why an indicator matters, not just that it fired.
- Design and validate SIEM detection rules (Splunk SPL + Elastic KQL)
- Investigate Windows endpoint telemetry using structured triage methodology
- Develop Sigma detection logic aligned to MITRE ATT&CK TTPs
- Perform threat hunting across log sources for persistence, lateral movement, and execution
- Conduct malware analysis and digital forensics in isolated lab environments
- Produce clear, escalation-ready case documentation for remote SOC workflows
- Google Cybersecurity Professional Certificate (Coursera)
- Cybersecurity for Everyone (Coursera)
- Self-studying toward BTL1 and CySA+
- Arabic (Native)
- French (Professional)
- English (Professional)
- Profile: github.com/KuRo0x
- Repositories: github.com/KuRo0x?tab=repositories

