Muhammad Imaad Ul Haq

SOC Analyst

Bengaluru, India

Certifications

Certified Ethical Hacker (CEH v13) EC-Council
Cisco Certified Network Associate (CCNA) Cisco

Projects & Labs

lab

Brute-Force Attack Detection – SSH & SMB

Simulated brute-force attacks on Linux and Windows systems and detected Event ID 4625 failures via Wazuh and Event Viewer. Mapped findings to MITRE ATT&CK framework (T1110, T1078) and validated account lockouts.

Wazuh, Windows Event Viewer, Event ID 4625, MITRE ATT&CK
lab

LOLBIN Detection – rundll32.exe

Detected rundll32 abuse via PowerShell using Sysmon and Splunk. Analyzed process chains and mapped findings to MITRE ATT&CK T1218.011.

Sysmon, Splunk, PowerShell, MITRE ATT&CK
lab

Digital Forensics & Incident Response (DFIR)

Recovered deleted files and analyzed disk images using forensic tools. Verified evidence integrity using MD5/SHA1 hashing and investigated AppData, NTFS artifacts, and user activity.

Autopsy, FTK Imager, MD5, SHA1
lab

End-to-End SOC Investigation

Performed reconnaissance, exploitation, and traffic analysis in a lab environment. Exploited VSFTPD 2.3.4 vulnerability and achieved root shell access.

Nmap, Metasploit, Wireshark
lab

Suricata IDS Configuration

Configured intrusion detection system on Kali Linux and generated alerts for Nmap scans using Emerging Threats (ET) rules.

Suricata, Kali Linux, ET rules
lab

Windows Log Analysis

Extracted Event ID 4625 logs from Windows systems and converted logs into structured CSV format for analysis.

Microsoft Log Parser, Windows Event Viewer

Skills

SIEM & Monitoring

WazuhSplunkWindows Event ViewerSysmonMicrosoft Log ParserAlert TriageCrowdStrike

Offensive Security

QualysNessusNmapMetasploitBurp Suite

GRC & Compliance

BitSightPanoraysCVSS ScoringMITRE ATT&CK

Network Security

WiresharkSuricataMXToolBoxPalo Alto

Operating Systems

Kali LinuxWindows 10/11Ubuntu Linux

Incident Response

AutopsyFTK ImagerIncident Response Lifecycle

Scripting & Automation

PowerShellGit/GitHub

Other

VMwareServiceNow