I will write custom siem detection rules
SOC Analyst IT Support Analyst
About this Gig
I'm a SOC-focused cybersecurity professional with hands-on experience in detection engineering across Wazuh, Splunk, and Microsoft Sentinel. I hold CompTIA CySA+ and an MSc in Cyber Security, and I've built and operated a multi-layer SOC lab with 40+ behaviour-based detections aligned to MITRE ATT&CK.
I write detection rules that identify attacker techniques, not just static indicators meaning your detections stay effective even when specific IOCs change.
What I can detect for you:
- Brute force / credential access attempts
- Suspicious PowerShell / process execution
- Lateral movement patterns
- Privilege escalation attempts
- Suspicious login/identity activity (including cloud identity)
- Persistence mechanisms
What you'll receive:
- Ready-to-use SPL (Splunk) or KQL (Sentinel) queries
- MITRE ATT&CK technique reference for each rule
- Plain-language explanation of what the rule catches and why
- Notes on tuning to reduce false positives
Before ordering: please message me with your log source (e.g., Windows Event Logs, Sysmon, firewall, cloud identity logs) and the specific behavior or technique you want detected, so I can confirm scope and required fields.

