Security monitoring
Splunk · Sentinel · SPL · KQL · Authentication analysis · Alert triage
Turn events into an investigation question.UAE · Open to SOC Analyst L1 opportunities
I’m Farhan. After 13 years keeping critical systems running, I’m turning that experience toward protecting them.
Years of troubleshooting taught me how systems fail. Now I’m learning how attackers exploit those failures—and how defenders find the evidence.
IT support, infrastructure,
identity, and NOC operations.
Enterprise support experience
at ENOC.
I bring the context behind the alert.
A VPN sign-in, a failing service, or an unexpected account change makes more sense when you understand the environment. My operations background gives me that starting point.
My next chapter is SOC analysis: validating signals, connecting authentication and endpoint evidence, understanding impact, and documenting clear next actions.
Infosys · Daimler data centre
KPFF Global
Expo 2020 Dubai
ENOC
Building toward SOC Analyst L1
Splunk · Sentinel · SPL · KQL · Authentication analysis · Alert triage
Turn events into an investigation question.AD / Entra ID · MFA · Conditional Access · Defender for Endpoint · Intune
Understand the user, device, and access context.Zeek · OPNsense · Suricata · TCP/IP · DNS · DHCP · Packet analysis
Follow activity beyond a single host.ITIL · Incident / problem / change · ServiceNow · BMC Remedy · Windows / Linux
Document clearly. Escalate responsibly. Own the outcome.Completed credentials, active study, and a practical roadmap toward a SOC Analyst L1 role.
ISC2 · CC
Microsoft · SC-300

EC-Council · CEH with AI
Cisco · CCNA
Also completed: cybersecurity internship with NIELIT, Government of India.
Security operations meets security fundamentals. Practicing Sentinel, Defender XDR, KQL, threats, and response decisions.
Connect network and endpoint evidence, map detections to MITRE ATT&CK, and document tuning and escalation decisions.
Bring operations experience, practical lab work, and an evidence-led mindset into a UAE security operations team.
Enterprise infrastructure, event operations, identity, and monitoring. Each role sharpened the discipline I bring to security.
ENOCIT Support Specialist & NOC AnalystDubai, UAE · Assignment through TransguardFeb 2022 — Present Current role
Expo 2020 DubaiIT Operations & Support EngineerDubai, UAEJun 2021 — Feb 2022
KPFF GlobalIT CoordinatorDubai, UAEAug 2015 — Jul 2020
InfosysSystem EngineerBangalore, India · Daimler Mercedes-Benz European Data CentreJun 2013 — Dec 2014Tools are a starting point. These case files show the questions, detection logic, and decisions behind my learning.
SSH brute-force investigation: from repeated authentication failures to a five-minute detection window and a search for successful access.
Illustrative signal pattern · KQL excerpt
Password-spraying analysis: distinguish targeted accounts from repeated attempts against a single user.
Connected Linux and Windows telemetry, practiced KQL, and configured an Ubuntu authentication analytics rule.
Onboarded Windows and Ubuntu to Defender for Endpoint and verified health and telemetry.
Zeek connection and DNS analysis, with a broader OPNsense and Suricata telemetry pipeline in development.
Velociraptor server and client deployment on ARM Linux, exploring authentication artifacts and endpoint evidence.
A personal environment connecting authentication tests, network visibility, endpoint evidence, and SIEM analysis. Explore the tools and how each layer supports an investigation.
Hiring for SOC Analyst L1 or cybersecurity operations?
I’d welcome a conversation about the experience I bring and the capability I’m building.