iqbal//soc

SOC analyst, Kuala Lumpur.
I investigate alerts, then fix the detection behind them.

Three years in a 24/7 security operations centre — triage, incident investigation, escalation, and the runbook and detection work that comes after. CySA+ certified. Currently going deep on detection engineering and AI-assisted triage.

ensign infosecurity · ensoc-mys · night shifts · qradar / sentinel / splunk / logrhythm

What I do

Alert triage and incident investigation across SIEM and EDR, IOC and phishing analysis, escalation and ticket discipline. The unglamorous part that decides whether a SOC works.

Detection notes

Lab write-ups: the rule, the telemetry, the false-positive result. Method first, no vendor slides. Read the notes.

Projects

Agentic security tooling I build and run myself — autonomous research agents on sanctioned platforms, and a client-side multi-model console. See projects.

Everything published here is lab-derived. Employer and client incident data never appears on this site, in any form. Anonymised case write-ups exist for interviews and stay private. Verifiable tooling lives on GitHub.

Current focus

Stack in daily use

IBM QRadarMicrosoft SentinelSplunk LogRhythmCrowdStrike FalconTrellix VectraTrend Micro ApexVirusTotal AbuseIPDBCisco TalosIBM X-Force MITRE ATT&CKSigmaPython