Skip to content
View Tohru-art's full-sized avatar
:shipit:
DFIR
:shipit:
DFIR

Highlights

  • Pro

Block or report Tohru-art

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Tohru-art/README.md

Will-Garlens Pierre's IT & Cybersecurity Portfolio 🔐

LinkedIn Portfolio TryHackMe Focus

SOC Analyst Intern at Log(N) Pacific with hands-on experience in vulnerability management, threat hunting, and security investigations using Microsoft Sentinel, Microsoft Defender for Endpoint, and KQL.

Currently pursuing a B.S. in Cybersecurity and Information Assurance at WGU while building expertise in Security Operations, Detection Engineering, and Microsoft security technologies.


📂 Featured Projects

🛡️ Vulnerability Management

Tenable · Azure VMs · PowerShell · DISA STIG

Implemented a vulnerability management program across Windows and Linux systems using Tenable and Azure virtual machines.

  • Reduced critical vulnerabilities by 100%
  • Reduced high severity vulnerabilities by 90%
  • Reduced medium severity vulnerabilities by 76%
  • Automated remediation of insecure protocols, weak ciphers, and privilege escalation vectors using PowerShell
  • Applied DISA STIG compliance standards across endpoints

🔍 Threat Hunting & Investigations

Microsoft Defender for Endpoint · KQL · MITRE ATT&CK

Conducted hypothesis-driven threat hunting to identify potential anonymous browsing activity within an enterprise environment.

  • Developed hunt hypotheses
  • Queried telemetry using KQL
  • Investigated process execution and network activity
  • Documented findings using SOC investigation methodology

Microsoft 365 · Microsoft Entra ID · Microsoft Sentinel · KQL · Business Email Compromise

Investigated suspicious identity activity involving anonymous IP sign-ins targeting a finance user in a Microsoft 365 environment.

The investigation focused on identifying attacker actions following successful authentication and determining whether cloud services, identity infrastructure, or email systems were abused.

  • Investigated anonymous IP sign-ins
  • Analyzed Microsoft Entra ID authentication events
  • Correlated cloud and identity telemetry
  • Investigated post-authentication activity
  • Documented findings and investigative methodology
  • Mapped attacker behavior to MITRE ATT&CK techniques

⚙️ Detection Engineering

KQL Detection Library (Building)

Microsoft Sentinel · Microsoft Defender for Endpoint · MITRE ATT&CK

Developing a personal library of KQL detections and analytics rules built from threat hunting exercises, SOC investigations, and security labs.

Current focus areas:

  • Password spraying detection
  • Anonymous IP sign-ins
  • Suspicious process execution
  • Persistence mechanisms
  • Privilege escalation activity
  • Potential command and control behavior

🧰 Technologies & Tools

Microsoft Sentinel Microsoft Defender for Endpoint KQL Microsoft Azure Microsoft Entra ID Tenable PowerShell Python Linux Windows


📚 Education & Professional Development

Status Item
In Progress B.S. Cybersecurity and Information Assurance, WGU
Preparing For CompTIA A+ (220-1201 / 220-1202)
Active Learning KQL Query Development
Active Learning Threat Hunting Methodologies
Active Learning Microsoft Sentinel Investigation Workflows
Active Learning Microsoft Defender for Endpoint Analysis
Practice Platform TryHackMe SOC Level 1
Practice Platform Log(N) Pacific Hunt Exercises

🎯 Current Focus Areas

  • Threat Hunting
  • Security Operations (SOC)
  • Detection Engineering
  • Microsoft Security Ecosystem
  • KQL Development
  • Incident Investigation
  • Vulnerability Management

Pinned Loading

  1. Vulnerability-Management-Program Vulnerability-Management-Program Public

  2. kql-detection-library kql-detection-library Public

    Production-ready KQL detection rules for Microsoft Sentinel and MDE, with MITRE ATT&CK mapping and tuning notes

  3. windows-11-stig-remediation windows-11-stig-remediation Public

    DISA STIG remediation scripts for Windows 11 - Log(N) Pacific Cyber Range Internship

    PowerShell

  4. HUNT-08-Second-Vector HUNT-08-Second-Vector Public

    Cloud BEC threat hunt report for Log(N) Pacific HUNT 08

    1