Blue Team · SOC · Incident Response

Hello, I'm Ghaliah

Dedicated to proactive defense in an evolving threat landscape. Secure. Resilient. Ready.

Cybersecurity shield illustration
Threat Detection
Network Analysis
Incident Response

Whoami

As a Computer Science graduate passionate about defensive cybersecurity, I transitioned from understanding how technology is built to mastering how it is defended. My expertise is focused on Blue Team operations, threat detection, and incident response.

Armed with specialized security certifications and hands-on experience in analyzing network traffic and configuring SIEM environments, I am dedicated to decoding complex data into proactive, resilient defenses that protect critical infrastructure.

Blue TeamSOC AnalysisSIEMIncident ResponseThreat Detection

Featured Projects

Project · 01

Wazuh SIEM Lab

This project demonstrates an enterprise-grade SIEM setup bridging defensive monitoring with active execution. It features a centralized Wazuh manager on Ubuntu Server orchestrating endpoint agents across both Linux and Windows environments. Built to handle real-world scenarios, the lab integrates File Integrity Monitoring (FIM) to trace unauthorized system alterations, while leveraging the VirusTotal API to continuously cross-reference hashes against global threat intelligence. Upon validating a malicious file, an integrated active response script automatically isolates or purges the threat, feeding detailed telemetry back to dynamic alerts and dashboards mapped directly against the MITRE ATT&CK framework.

Project · 02

Network Traffic Analyzer

Designed to address the critical need for objective, high-speed network reconnaissance triage, this tool automates deep packet analysis without the need for manual Wireshark filtering. Leveraging Python and the Scapy library, it handles core parsing through rdpcap() to break down live or captured traffic. The analyzer isolates network reconnaissance by tracking SYN packet thresholds for port scan detection, identifies web-layer threats via suspicious path matching, and monitors potential data exfiltration through DNS query length baselining. All findings are structured instantly into automated text report files to streamline incident response workflows.

Project · 03

Log & Brute Force Analyzer

Built to simulate real-world security monitoring, this utility automates log parsing to spot critical authentication anomalies. The tool uses a dual-component design: a simulation engine that generates activity logs with a mix of normal access and malicious traffic, and an analytics core that continuously scans the telemetry. By analyzing failed login patterns and tracking threshold spikes from suspicious IP addresses, it distinguishes legitimate user friction from live brute-force attempts. Once a pattern matches, the script bypasses manual inspection to output a clean, defensive report.txt file containing the precise timestamps and threat intelligence needed for immediate triage.

Professional Certifications

CompTIA CySA+

Issued April 2026

Advanced into tactical blue team operations, continuous monitoring, and security telemetry analysis. Gained hands-on proficiency in leveraging SIEM environments, applying threat intelligence, and managing structured incident response workflows.

Verify Credentials

CompTIA Security+

Issued January 2026

Validated fundamental expertise in network security, risk mitigation, and infrastructure protection. Established the core cryptographic and access control baselines required to implement proactive security controls across enterprise environments.

Verify Credentials

Courses & Learning

Continuous Growth
Through Learning.

Alongside my academic foundation and core hands-on labs, I consistently expand my technical horizons through specialized industry training. These curated courses sharpen my practical skills in digital defense, cloud architectures, and security automation.

4 certified programs
Course 01 · TryHackMe

Cybersecurity 101

A foundational hands-on learning path covering essential security methodologies, network concepts, and defensive security environments.

Defensive SecurityNetwork SecurityWeb App SecurityLinux Basics
Course 02 · Google

Security Principles in Cloud Computing

An introductory course exploring cloud infrastructure security, shared responsibility models, and identity management.

Cloud SecurityIAMRisk MitigationInfrastructure Security
Course 03 · Google

Automate Cybersecurity Tasks with Python

A practical, development-focused course leveraging Python scripting for security operations and task automation.

Python ScriptingAutomationLog ParsingSecurity Operations
Course 04 · Misk x STC

Incident Response Analysis — Virtual Work Experience

A simulated professional training experience focused on real-world incident handling, threat mitigation, and security operations.

Incident ResponseThreat AnalysisAlert TriageSOC Workflows

Skills

SIEM Monitoring
Analyzing centralized security telemetry to maintain continuous infrastructure visibility.
Log Parsing & Triage
Inspecting system and authentication logs to detect anomalous behavioral patterns.
Packet Analysis & Forensics
Inspecting live network traffic to identify payloads and malicious indicators.
EDR Management
Monitoring host-level activities and deploying agents to secure multi-OS environments.
Threat Intelligence
Mapping adversary tactics using global frameworks like MITRE ATT&CK.
Incident Containment
Applying structured, active response workflows to swiftly isolate compromised assets.
Vulnerability Assessment
Scanning digital infrastructures to identify security gaps and prioritize risks.
Security Scripting
Writing custom scripts to automate data parsing and speed up triage times.
Access Hardening
Auditing user permissions and configurations to enforce least-privilege principles.
Network Security
Implementing defensive controls and firewalls to protect data in transit.

Tools I use

Wireshark
Splunk
Nmap
Wazuh
Linux
Windows
Python

Learning Roadmap

  • Completed · Step 01

    Security Fundamentals

  • Completed · Step 02

    Linux & OS Fundamentals

  • Completed · Step 03

    Network Fundamentals

  • Completed · Step 04

    Security Skills

  • Completed · Step 05

    Blue Team Projects

  • Completed · Step 06

    Security+ Certification

  • Completed · Step 07

    CySA+ Certification

  • In Progress · Step 08

    SOC L1

Contact Me

Open to entry-level Blue Team, SOC analyst, and incident response opportunities. Reach out through the form or any of the channels below.

Riyadh, Saudi Arabia