I will write custom siem detection rules

United Kingdom

I speak English

SOC Analyst IT Support Analyst

I am a SOC-focused cybersecurity professional specialising in detection engineering, SIEM operations, and behaviour-based threat investigation. I have hands-on experience building multi-layer SOC envi...
About this Gig

I'm a SOC-focused cybersecurity professional with hands-on experience in detection engineering across Wazuh, Splunk, and Microsoft Sentinel. I hold CompTIA CySA+ and an MSc in Cyber Security, and I've built and operated a multi-layer SOC lab with 40+ behaviour-based detections aligned to MITRE ATT&CK.

I write detection rules that identify attacker techniques, not just static indicators meaning your detections stay effective even when specific IOCs change.

What I can detect for you:

  • Brute force / credential access attempts
  • Suspicious PowerShell / process execution
  • Lateral movement patterns
  • Privilege escalation attempts
  • Suspicious login/identity activity (including cloud identity)
  • Persistence mechanisms

What you'll receive:

  • Ready-to-use SPL (Splunk) or KQL (Sentinel) queries
  • MITRE ATT&CK technique reference for each rule
  • Plain-language explanation of what the rule catches and why
  • Notes on tuning to reduce false positives

Before ordering: please message me with your log source (e.g., Windows Event Logs, Sysmon, firewall, cloud identity logs) and the specific behavior or technique you want detected, so I can confirm scope and required fields.

My Portfolio