Muhammad Imaad Ul Haq
SOC Analyst
Bengaluru, India
Certifications
Projects & Labs
Brute-Force Attack Detection – SSH & SMB
Simulated brute-force attacks on Linux and Windows systems and detected Event ID 4625 failures via Wazuh and Event Viewer. Mapped findings to MITRE ATT&CK framework (T1110, T1078) and validated account lockouts.
LOLBIN Detection – rundll32.exe
Detected rundll32 abuse via PowerShell using Sysmon and Splunk. Analyzed process chains and mapped findings to MITRE ATT&CK T1218.011.
Digital Forensics & Incident Response (DFIR)
Recovered deleted files and analyzed disk images using forensic tools. Verified evidence integrity using MD5/SHA1 hashing and investigated AppData, NTFS artifacts, and user activity.
End-to-End SOC Investigation
Performed reconnaissance, exploitation, and traffic analysis in a lab environment. Exploited VSFTPD 2.3.4 vulnerability and achieved root shell access.
Suricata IDS Configuration
Configured intrusion detection system on Kali Linux and generated alerts for Nmap scans using Emerging Threats (ET) rules.
Windows Log Analysis
Extracted Event ID 4625 logs from Windows systems and converted logs into structured CSV format for analysis.