SOC Analyst Intern at Log(N) Pacific with hands-on experience in vulnerability management, threat hunting, and security investigations using Microsoft Sentinel, Microsoft Defender for Endpoint, and KQL.
Currently pursuing a B.S. in Cybersecurity and Information Assurance at WGU while building expertise in Security Operations, Detection Engineering, and Microsoft security technologies.
Tenable · Azure VMs · PowerShell · DISA STIG
Implemented a vulnerability management program across Windows and Linux systems using Tenable and Azure virtual machines.
- Reduced critical vulnerabilities by 100%
- Reduced high severity vulnerabilities by 90%
- Reduced medium severity vulnerabilities by 76%
- Automated remediation of insecure protocols, weak ciphers, and privilege escalation vectors using PowerShell
- Applied DISA STIG compliance standards across endpoints
Microsoft Defender for Endpoint · KQL · MITRE ATT&CK
Conducted hypothesis-driven threat hunting to identify potential anonymous browsing activity within an enterprise environment.
- Developed hunt hypotheses
- Queried telemetry using KQL
- Investigated process execution and network activity
- Documented findings using SOC investigation methodology
Microsoft 365 · Microsoft Entra ID · Microsoft Sentinel · KQL · Business Email Compromise
Investigated suspicious identity activity involving anonymous IP sign-ins targeting a finance user in a Microsoft 365 environment.
The investigation focused on identifying attacker actions following successful authentication and determining whether cloud services, identity infrastructure, or email systems were abused.
- Investigated anonymous IP sign-ins
- Analyzed Microsoft Entra ID authentication events
- Correlated cloud and identity telemetry
- Investigated post-authentication activity
- Documented findings and investigative methodology
- Mapped attacker behavior to MITRE ATT&CK techniques
Microsoft Sentinel · Microsoft Defender for Endpoint · MITRE ATT&CK
Developing a personal library of KQL detections and analytics rules built from threat hunting exercises, SOC investigations, and security labs.
Current focus areas:
- Password spraying detection
- Anonymous IP sign-ins
- Suspicious process execution
- Persistence mechanisms
- Privilege escalation activity
- Potential command and control behavior
| Status | Item |
|---|---|
| In Progress | B.S. Cybersecurity and Information Assurance, WGU |
| Preparing For | CompTIA A+ (220-1201 / 220-1202) |
| Active Learning | KQL Query Development |
| Active Learning | Threat Hunting Methodologies |
| Active Learning | Microsoft Sentinel Investigation Workflows |
| Active Learning | Microsoft Defender for Endpoint Analysis |
| Practice Platform | TryHackMe SOC Level 1 |
| Practice Platform | Log(N) Pacific Hunt Exercises |
- Threat Hunting
- Security Operations (SOC)
- Detection Engineering
- Microsoft Security Ecosystem
- KQL Development
- Incident Investigation
- Vulnerability Management



