SOC analyst / Security engineer / Wazuh ambassador

Saif.SOC Analyst

I turn security telemetry into useful detections, clearer investigations, and faster response.

Based in Lahore, Pakistan. I work across SIEM, endpoint and network monitoring, threat intelligence, and SOC automation — from the first alert to the final case notes.

40+FYP use cases
4Featured projects
3Countries served
Wazuh Ambassador · BS Information Technology, University of the Punjab
Portrait of Saif Ullah
SOC / INVESTIGATION FLOW
FROM EVENT TO ACTION
01 / CollectEndpoint · Network · Cloud
02 / DetectWazuh · Custom rules
03 / EnrichOpenCTI · Threat intel
04 / Respondn8n · IRIS · Slack
Focused on actionable alerts, clear evidence, and repeatable response.
A closer look

Inside my SOC workspace.

A short, animated introduction to the areas I work in. The lines describe my portfolio; this is a visual demo, not a live security feed.

saif@soc — portfolio

Saif Ullah is a SOC Analyst at DWP Group and a Wazuh Ambassador. His work includes Wazuh detection, n8n automation, OpenCTI enrichment, DFIR-IRIS cases and the 360 Fortress final year project.

01 / Selected work

Built for real security operations.

Deployments, detection engineering, and SOC workflows across client and lab environments.

PROJECT / 01Final year project

360 Fortress

A multi-layer cyber defense system developed with a New Zealand-based company. Designed 40+ use cases spanning endpoint, network, cloud, AI and LLM security, with threat intelligence and automated response.

WazuhSOARDetection engineering
PROJECT / 02SOC operations

Wazuh → n8n → OpenCTI → IRIS

Integrated alerts with enrichment, case management, and Slack notifications to support triage and investigation in a practical SOC workflow.

n8nOpenCTIDFIR-IRIS
See the architecture and replay it ↓
PROJECT / 03Cloud SIEM

AmaraTechIT / AWS

Deployed Wazuh on AWS with BYOD onboarding, FIM, Microsoft 365 integration, multi-tenant configuration, custom branding and domain setup.

AWSMicrosoft 365Wazuh
PROJECT / 04Client delivery

Wazuh dashboard branding

Customized a client Wazuh interface, including its login page, favicons, banners, report logos and dashboard titles.

UI customizationReportsBranding
02 / Architecture

An open-source SOC, from alert to case.

I designed and built this stack hands-on. Wazuh detects, n8n filters, OpenCTI enriches, DFIR-IRIS tracks the case and Slack tells the analyst.

Diagram of the open-source SOC. Wazuh agents on Windows 10/11 and Ubuntu Linux endpoints send logs to the Wazuh SIEM. Severity-based webhooks pass alerts to Shuffle SOAR and n8n, which create cases in DFIR-IRIS and post to Slack #soc-alerts. OpenCTI supplies IOC feeds from AbuseIPDB, MalwareBazaar, MITRE ATT&CK, URLhaus, VirusTotal and AlienVault or ThreatFox.
Opensource SOC Architecture & Automated Incident Flow. Endpoint telemetry reaches Wazuh, automation filters by severity, and each real incident becomes an IRIS case and a Slack alert.Open full size ↗

Replay an incident

Pick an alert and watch it move through the stack. Low-severity alerts stop at the filter, so no case is opened for them.

Sample data, not a live feed
  1. EndpointWazuh agentWaiting for an event
  2. WazuhSIEM and detectionWaiting for logs
  3. n8nSeverity filterWaiting for an alert
  4. OpenCTIIOC enrichmentWaiting for IOCs
  5. DFIR-IRISCase managementWaiting for a verdict
  6. Slack#soc-alertsWaiting for a case
DFIR-IRIS caseWaiting
Opens when an alert passes the filter and the IOC check.
Slack #soc-alertsWaiting
Posts once the case exists.

Replay totals0 alerts seen0 filtered out0 cases opened

Replay of an alert moving through the stack: an endpoint event is detected by Wazuh, filtered by severity in n8n, checked against threat intelligence in OpenCTI, opened as a case in DFIR-IRIS and announced in Slack. Low-severity alerts stop at the filter. All values shown are sample data.

The stack, layer by layer

Each layer is open source, so a team can adopt it without licence fees. Slack is the one exception, and it is easy to swap.

Endpoints and data sourcesWazuh agents

Agents on Windows 10/11 and Ubuntu Linux machines send logs and telemetry. Agent groups (Windows, Linux, default) keep each type of machine on its own configuration.

Wazuh agentWindows 10/11Ubuntu LinuxAgent groups

Core SIEMWazuh

Wazuh generates the security alerts and forwards them by severity-based webhooks, so only what matters moves on.

WazuhCustom rulesSeverity-based webhooks

Orchestration and automationShuffle SOAR, n8n

Workflows filter alerts by severity and start automated case creation, which removes the copy-and-paste work from triage.

Shuffle SOARn8n workflows

Threat intelligenceOpenCTI

OpenCTI brings IOC feeds into the flow, so an IP, hash or URL is checked against known bad infrastructure before an analyst opens the alert.

AbuseIPDBMalwareBazaarMITRE ATT&CKURLhausVirusTotalAlienVault / ThreatFox

Incident responseDFIR-IRIS

Every alert that passes the filter becomes a case automatically, with the alert context attached, so investigation starts with evidence instead of a blank page.

DFIR-IRISAutomated case creation

Communication and escalationSlack

Real-time notifications in #soc-alerts show the alert severity and Wazuh rule, the agent and event details, the IRIS case ID with a direct link, and the analyst escalation status. Mattermost or Rocket.Chat can fill the same slot for a fully open-source stack.

SlackBlock Kit alerts#soc-alerts

Want something like this for your team?

I built and ran this end to end. If you're weighing an open-source SOC, get in touch and we can talk through your setup.

03 / Experience

Hands-on, across the SOC.

SOC Analyst L1

DWP Group · Lahore

Investigate endpoint, network and application alerts; tune Wazuh detections and dashboards; connect Wazuh, n8n, OpenCTI, DFIR-IRIS and Slack for enrichment and case tracking.

Security Engineer

IT Fortress · Remote / New Zealand

Promoted from SOC Analyst within six months. Designed multi-tenant Wazuh deployments, built detection use cases and automated alerting with security and SOAR integrations.

Associate Security Engineer

Ebryx Pvt Ltd · Lahore

Triaged endpoint, network and cloud alerts with CrowdStrike, VIPRE, ELK Stack, Wazuh and Microsoft Sentinel; documented investigations and escalated findings.

SOC Analyst

ITSOLERA Pvt Ltd · Islamabad

Supported client security monitoring, incident documentation, Wazuh detections and practical SOC training.

Wazuh Ambassador

Wazuh Community · Pakistan

Share practical content, labs and SOC use cases focused on open-source security monitoring. View official profile ↗

04 / Toolkit

Where I work best.

SIEM & detection

Wazuh, Microsoft Sentinel, ELK Stack, custom rules, FIM, log analysis

SOAR & cases

n8n, Shuffle, DFIR-IRIS, TheHive, response workflows

Endpoint & network

CrowdStrike, VIPRE, Sysmon, Suricata, Snort, pfSense, Sophos

Cloud & intelligence

AWS, Azure, Microsoft 365, OpenCTI, VirusTotal, AbuseIPDB

06 / Résumé & learning

Experience in one place.

Download my current résumé and review selected training.

Saif Ullah — Résumé

My attached two-page résumé, covering SOC experience, projects, technical skills and training.

Download résumé ↓

Selected learning

Cisco Junior Cybersecurity Analyst Career Path, Ethical Hacker and Cyber Threat Management; Microsoft Learn modules in Sentinel, KQL, Defender for Endpoint and Defender XDR.

View verified badges ↗
07 / Contact

Let's talk security.

Reach out about SOC operations, Wazuh deployments, detection use cases, or security automation.

Send an email ↗