$ whoami

John Jebas

Enterprise SOC Tier 1 & 2 Security Analyst with 1 year 5 months of hands-on operations experience at TVS Electronics. Specializing in Microsoft Sentinel SIEM detection architecture, KQL threat hunting heuristics, endpoint containment with Bitdefender EDR, and OWASP-aligned vulnerability assessment/penetration testing (VAPT). Splunk certified and Certified Ethical Hacker (CEH) certified.

Chennai, Tamil Nadu · +91 89398 90285
jebas_soc_shell.sh
● SECURE SHELL
Initializing JohnJebas SOC console v1.7...
Connection established with Sentinel SIEM agent.
Type 'help' to view list of available cyber commands.
john-jebas@soc-hub:~$
1.5 yrs
SOC Experience
Tier 1&2
Analyst Level
MITRE
ATT&CK Aligned
OWASP
Top 10 Testing
00

Live Global Threat Intelligence

● Real-time Feed
TVS SOC — Live Threat Intelligence Map
NODE: Chennai, IN [9°N 80°E]BLOCKED: 0FEED: ● LIVE
MoscowBeijingN. VirginiaFrankfurtLagosGuangzhouTehranTVS SOCCHENNAI, IN
Critical High SOC Node

Active Incident Feed

SENTINEL SIEM
Awaiting live telemetry feed...
Blocked
0
Status
OPERATIONAL
◎

Detect

SIEM · KQL · MITRE

Architect and tune analytics rules across Microsoft Sentinel with hypothesis-driven KQL hunting queries. Map detections to MITRE ATT&CK tactics, reduce alert fatigue via dynamic threshold calibration, and achieve sub-5-minute mean-time-to-detect (MTTD) across Windows, Linux, identity and network log sources.

  • 92% alert coverage rate
  • KQL rule authoring
  • Sub-5min MTTD
  • MITRE-mapped detections
⬡

Respond

IR · EDR · SOAR

Drive structured incident lifecycle management from initial triage to root cause analysis and post-incident review. Execute endpoint isolation, credential resets, and phishing campaign containment using Bitdefender EDR and Logic Apps SOAR playbooks. Deliver evidence-backed closure reports with NIST SP 800-61 alignment.

  • Full lifecycle IR
  • Endpoint containment
  • SOAR playbooks
  • NIST 800-61 aligned
◈

Harden

VAPT · CVE · OWASP

Conduct authenticated OWASP Top 10 web application assessments and CVSS v3.1-scored vulnerability scanning with Burp Suite Pro and Nessus. Deliver prioritised remediation reports with reproducible PoCs, exploit validation, and developer-ready fix guidance aligned to business risk exposure.

  • OWASP Top 10 testing
  • CVSS v3.1 scoring
  • Burp Suite Pro
  • Validated PoC delivery
01

Experience

Full-TimeActive · 1y 5m

Cyber Security Analyst — SOC Tier 1 & 2

TVS Electronics Ltd. · Chennai, Tamil Nadu · March 2025 – Present

24/7
SOC Coverage
92%
Alert Coverage
<5 min
Avg MTTD
NIST
IR Framework

Embedded within a 24×7 enterprise Security Operations Center at TVS Electronics, operating across the full defensive lifecycle — from real-time SIEM alert triage and KQL-driven threat hunting in Microsoft Sentinel to endpoint isolation via Bitdefender EDR, SOAR playbook automation, CVSS-ranked vulnerability management and OWASP-aligned web application penetration testing. Responsible for both detection engineering and incident response closure reporting.

SIEM

SIEM Monitoring & Threat Hunting

Front-line monitoring of enterprise log sources in Microsoft Sentinel, turning raw telemetry into actionable incidents.

  • Triaged daily alert queues across Windows, Linux, firewall, identity and endpoint log sources, classifying true/false positives with documented rationale.
  • Wrote and iterated KQL hunting queries over SecurityEvent, SigninLogs and DeviceEvents to surface anomalies that no existing rule covered.
  • Correlated multi-source events into single incidents to remove duplicate noise and give responders one timeline per intrusion attempt.
  • Microsoft Sentinel
  • KQL
  • Log Analytics
  • Azure AD Logs

⬡ TA0001 Initial Access · TA0006 Credential Access

DETECTION

Detection Engineering & Automation

Improved detection quality by tuning what fires, when it fires, and what happens automatically afterwards.

  • Authored and tuned Sentinel analytics rules, adjusting thresholds, entity mappings and suppression windows to cut alert fatigue without losing coverage.
  • Built automation playbooks for repetitive triage steps — enrichment, entity lookup and analyst notification — shortening time-to-first-action.
  • Mapped detections to MITRE ATT&CK techniques so coverage gaps were visible and prioritised rather than assumed.
  • Analytics Rules
  • Logic Apps Playbooks
  • MITRE ATT&CK
  • SOAR Concepts

⬡ Detection coverage mapping

IR

Incident Response & Investigation

Owned incidents end-to-end from detection through containment, remediation and closure reporting.

  • Investigated phishing campaigns — header analysis, URL and attachment detonation, affected-user scoping and mailbox-level cleanup.
  • Handled brute-force and impossible-travel sign-in incidents: validated source IP reputation, confirmed compromise, forced credential resets.
  • Documented each incident with timeline, root cause, impact and remediation actions, and fed findings back into detection tuning.
  • Sentinel Incidents
  • VirusTotal
  • AbuseIPDB
  • Email Header Analysis

⬡ TA0043 Recon · TA0011 Command & Control

VAPT

Vulnerability Assessment & Penetration Testing

Offensive-side testing of web applications and internal systems, reported with reproducible evidence.

  • Performed authenticated and unauthenticated web app testing against the OWASP Top 10 — SQL injection, XSS, broken access control, auth and session flaws.
  • Validated scanner output manually to eliminate false positives before anything reached the remediation backlog.
  • Delivered VAPT reports with reproduction steps, CVSS-scored severity, business impact and concrete developer-facing fixes.
  • Burp Suite Pro
  • OWASP ZAP
  • Nmap
  • Nessus
  • Kali Linux

⬡ OWASP Top 10 aligned

VM

Vulnerability & Patch Management

Continuous assessment of the endpoint and server estate with risk-ranked remediation tracking.

  • Ran scheduled authenticated scans across Windows and Linux endpoints, tracking newly introduced CVEs between cycles.
  • Prioritised remediation using CVSS severity combined with asset exposure and exploit availability rather than raw score alone.
  • Coordinated with IT teams on patch cycles and re-validated closure with follow-up scans.
  • SecPod SanerNow
  • Nessus
  • CVE / CVSS
  • Patch Cycles

⬡ Exposure reduction

EDR

Endpoint Detection & Response

Day-to-day ownership of endpoint protection posture and malware investigation across the estate.

  • Investigated EDR detections — process trees, parent-child anomalies, persistence artefacts and suspicious script execution.
  • Contained compromised hosts through isolation and blocked malicious hashes and processes across the fleet.
  • Reviewed policy exclusions and endpoint health to keep coverage complete and false positives low.
  • Bitdefender EDR
  • Windows Event Logs
  • Process Analysis
  • Host Isolation

⬡ TA0002 Execution · TA0003 Persistence

INTEL

Threat Intelligence & Reporting

Enriched investigations with external context and turned technical findings into readable reporting.

  • Validated IPs, domains, URLs and file hashes against VirusTotal and open-source threat intel before blocking or escalating.
  • Maintained IOC context for recurring campaigns so repeat activity was recognised immediately.
  • Produced incident and assessment reports for both technical responders and non-technical stakeholders.
  • VirusTotal
  • OSINT Feeds
  • IOC / IOA
  • Reporting

⬡ Enrichment & attribution

02

Technical Skills

92%
SIEM

SIEM & Threat Detection

Daily driver for 24x7 monitoring — building, tuning and hunting across Microsoft Sentinel log sources.

Microsoft Sentinel92%
KQL Query Writing90%
Analytics Rule Tuning85%
Threat Hunting82%
  • ▸Authored KQL analytics rules across sign-in, endpoint and firewall tables with tuned thresholds to cut false positives.
  • ▸Ran hypothesis-driven hunts on anomalous authentication, lateral movement and persistence patterns.
  • ▸Built workbooks and scheduled queries for daily SOC shift handover and management reporting.
  • Sentinel
  • KQL
  • Log Analytics
  • Workbooks
  • Alert Triage
  • Playbooks

Framework · MITRE ATT&CK detection coverage mapping

85%
VAPT

VAPT & Security Testing

Web and network assessments end-to-end — recon, exploitation validation, and developer-ready remediation reporting.

Burp Suite Pro86%
Nessus / SanerNow84%
Nmap & Recon82%
Manual Exploitation75%
  • ▸Performed authenticated and unauthenticated web app tests covering injection, access control and session flaws.
  • ▸Validated scanner output manually to eliminate false positives before raising findings.
  • ▸Scored issues with CVSS v3.1 and delivered reproducible PoCs with fix guidance to engineering teams.
  • Burp Suite
  • Nessus
  • Nmap
  • OWASP ZAP
  • SanerNow
  • CVSS v3.1

Framework · OWASP Top 10 / OWASP Testing Guide

88%
IR

EDR & Incident Response

Endpoint containment and full incident lifecycle — from first alert to root cause and closure notes.

Bitdefender EDR88%
Malware Triage80%
Containment & Isolation86%
Forensic Timelining74%
  • ▸Investigated endpoint detections through process trees, parent-child anomalies and persistence artifacts.
  • ▸Isolated compromised hosts, killed malicious processes and coordinated reimaging with IT.
  • ▸Documented incidents with timeline, impact, root cause and preventive actions.
  • Bitdefender EDR
  • IOC / IOA
  • VirusTotal
  • Sandboxing
  • SOAR Concepts

Framework · NIST SP 800-61 incident handling lifecycle

80%
INFRA

Networking & Platforms

Protocol-level understanding that underpins traffic analysis, log interpretation and detection accuracy.

TCP/IP & DNS84%
Windows Internals78%
Linux (Kali)78%
Firewall & Proxy Logs76%
  • ▸Analysed packet captures and firewall logs to confirm C2 beaconing and data exfiltration attempts.
  • ▸Correlated Windows event IDs (4624/4625/4688/7045) into detection logic.
  • ▸Reviewed DNS and proxy telemetry for tunnelling and newly registered domain access.
  • TCP/IP
  • DNS
  • HTTP/HTTPS
  • Windows
  • Kali Linux
  • Wireshark
  • Firewalls

Framework · Cyber Kill Chain traffic-stage analysis

72%
AUTO

Scripting & Automation

Query and script work to remove manual toil from triage, enrichment and reporting workflows.

KQL90%
SQL74%
Python65%
Bash62%
  • ▸Wrote reusable KQL functions for repeated triage lookups across analysts.
  • ▸Used Python scripts for bulk IOC enrichment and report data formatting.
  • ▸Automated recurring evidence collection steps with shell one-liners.
  • KQL
  • SQL
  • Python
  • Bash
  • REST APIs
  • Automation Playbooks

Framework · SOC toil reduction / analyst enablement

MITRE ATT&CK Matrix Detection Coverage Console

TA0001 · Tactic

Initial Access

The adversary is trying to get into your network via perimeter vectors.

Applied Detections:
Sentinel KQL Rule · T1566.001STATUS: DEPLOYED
OfficeAttachmentDeliveryEvents
| where FileExtension in ("exe", "lnk", "vbs", "ps1")
| where ThreatTypes has "Malware" or ThreatTypes has "Phish"
| project Timestamp, SenderAddress, RecipientAddress, FileName
03

Certifications & Education

SCANNING

Vesting Credential Signatures

Starting signature checks...
Status: TLS Signature Verification Engine Ingesting
  • Certified Ethical Hacker (CEH)

    EC-Council

    Completed
  • Certified Cybersecurity Educator Professional (CCEP)

    Red Team Leaders

  • Security Operations and Defense Analyst

    Splunk

  • Understanding Threats and Attacks

    Splunk

  • Cybersecurity Essentials

    Cisco Networking Academy

  • SanerNow Cyber Hygiene Platform Training

    SecPod

Education

B.Tech — Computer Science and Engineering

Dr. M.G.R. Educational and Research Institute, Chennai

2020 – 2024 · CGPA 7.91

Beyond Work

  • Active on TryHackMe and Hack The Box — hands-on labs and CTF challenges.
  • Focused on SOC operations, threat hunting, incident response and cloud security.
04

Projects

IFLEX TRAX 1.7 — Facebook-Style User Registration System

Collaboratively developed a Facebook-style user registration system with secure signup, form validation, database integration and a responsive interface.

  • Python
  • Django
  • MySQL
  • HTML
  • CSS
  • JavaScript

$ contact --open

Open to SOC & Security Analyst roles

© 2026 John Jebas · Chennai, India