Rimsha Razi

Security Operations Center (SOC) Analyst | Threat Detection & Incident Response

Cybersecurity specialist focused on threat detection, systematic log analysis, and automated incident response. Specialized in SIEM telemetry monitoring, MITRE ATT&CK framework mapping, and Python security scripts.

Security Operations (SOC) MITRE ATT&CK Mapping Log Analysis & SIEM Python Security Automation Threat Detection

Interactive Tool: SIEM Log Parser & Brute-Force Detector

Technical Architecture & Specification Document ↗ Open PDF in New Tab

This tool executes live Python detection logic inside your browser using PyScript. It parses SSH authentication logs to detect brute-force and password spraying attacks mapped to MITRE ATT&CK T1110.

Click the button above to execute Python detection engine...

Automatic Log File Scanner

Drop your local syslog or auth log file below for instant detection:

Upload or drop a log file above to run automatic analysis...

Cybersecurity Home Lab Projects

1. SIEM Log Telemetry & Endpoint Monitoring (Wazuh + pfSense)
Architected a virtualized security home lab utilizing pfSense firewall rules and Wazuh SIEM agents across Windows and Linux endpoints. Simulated lateral movement and brute-force attacks to create custom XML detection rules and generate alert dashboards.
Key Skills: Wazuh SIEM, pfSense, Sysmon, Custom Detection Rules, Windows Event Logs
2. Automated Threat Intelligence & Beaconing Detection
Developed custom Python scripts to parse NetFlow and network connection logs. Calculated mathematical variance across outbound connection timestamps to flag automated C2 (Command and Control) beaconing activity mapped to MITRE ATT&CK T1071.
Key Skills: Python, Threat Hunting, Network Telemetry Analysis, MITRE ATT&CK

Technical Tooling & Core Competencies