Skip to content
View NamrataSonii's full-sized avatar

Block or report NamrataSonii

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
NamrataSonii/README.md

Hi, I'm Namrata Soni

Cybersecurity Postgraduate | SOC | Detection Engineering | Threat Intelligence


About Me

  • Postgraduate student specializing in SOC Operations, Malware Analysis, and Cyber Threat Intelligence
  • Built a SOC Detection Lab simulating a complete privilege escalation attack chain using Splunk and Sysmon
  • Experienced with SIEM platforms, MITRE ATT&CK mapping, and incident response workflows through academic projects and two internships
  • Currently focused on Detection Engineering and Blue Team operations
  • Looking for a Security Operations / SOC Analyst role

SOC Detection Lab

My most significant project — a fully functional home lab built to detect and investigate real attack techniques. Attack chain simulated:

Account Created → Brute Force → Successful Login → PowerShell Execution → Privilege Escalation

What it covers:

  • 5 SPL detection queries mapped to MITRE ATT&CK
  • Incident response playbooks for every detection
  • Full Splunk + Sysmon + Windows Event Log pipeline
  • Complete setup documentation View the SOC Detection Lab

Skills

Blue Team: SOC Operations Detection Engineering Incident Response Log Analysis Threat Hunting Malware Analysis Cyber Threat Intelligence

Tools: Splunk Sysmon Microsoft Sentinel Defender XDR Wireshark Burp Suite Metasploit Nmap Remnux

Frameworks: MITRE ATT&CK Cyber Kill Chain ISO 27001 NIST

Languages: Python SQL Scripting


Projects

Project Description Tools
SOC Detection Lab Detects privilege escalation attack chain end-to-end Splunk, Sysmon, Windows Event Logs
CTI Reports In-depth threat intelligence reports on APT40, DarkHotel, and Equation Group with IOCs and MITRE ATT&CK mapping OSINT, VirusTotal, MITRE ATT&CK
Cybersecurity Attacks and Frameworks Documentation of attack techniques and frameworks MITRE ATT&CK, Cyber Kill Chain
Static Malware Detection (Research) ML-based malware classification using entropy analysis Python, Machine Learning
Malware Analysis Lab Static and dynamic analysis of malware samples REMnux, Virtual Machines
Vulnerability Assessment Web application vulnerability scanning and reporting Burp Suite

Certifications

  • Google Cybersecurity Professional Certification
  • Defronix Certified Junior Security Practitioner
  • ISO/IEC 27001 Information Security Management
  • arcX Cyber Threat Intelligence 101

Experience

Cybersecurity Intern — CyberMSI (Aug 2024 – Sep 2024)

Triaged alerts in Microsoft Sentinel and Defender XDR, identified malicious indicators, and supported incident response workflows.

Cybersecurity Intern — ShadowFox (May 2024 – Jun 2024)

Conducted vulnerability assessments, analyzed network traffic with Wireshark, and documented exploitation findings.


Connect With Me

LinkedIn GitHub

Pinned Loading

  1. SOC-Detection-Lab SOC-Detection-Lab Public

    Built a SOC Detection Lab using Splunk Enterprise and Sysmon to detect and investigate Windows security events.

    1

  2. Cybersecurity-Attacks-and-Frameworks Cybersecurity-Attacks-and-Frameworks Public

    Documentation of common cyber attack types and security frameworks.

  3. Linux-Fundamentals Linux-Fundamentals Public

    Documenting my Linux Fundamentals learning journey, concepts, commands, and hands-on notes

  4. NamrataSonii NamrataSonii Public

  5. Protocols Protocols Public

    Exploring how systems talk to each other — documentation and deep dives into protocols.

  6. Threat-Intelligence-Reports Threat-Intelligence-Reports Public

    In-depth threat intelligence reports on APT40, DarkHotel, and Equation Group — including IOCs, TTPs, and MITRE ATT&CK mapping, built using OSINT and VirusTotal analysis.