OPEN TO OPPORTUNITIES LAHORE, PAKISTAN

Ahmed Sajid Butt SOC Analyst L1 / Detection Engineer

I investigate incidents, hunt for what alerts miss, and build detection content from the ground up, across Microsoft Defender XDR, Wazuh, and the ELK Stack. Recent Computer Science graduate with hands-on SOC lab work and a completed cybersecurity internship behind me.

14Alerts correlated
in one investigation
7ATT&CK techniques
executed & analyzed
4Endpoints onboarded
via GPO + Intune
3Detection labs
built end to end
01

Case Files

CASE // VIGIL-2026 Featured

Vigil: SOC Detection Lab & Incident Response

A self built detection lab on Zorin OS running Wazuh SIEM, OpenSearch, and TheHive case management behind an Nginx reverse proxy. Simulated a four stage web application compromise end to end, each stage independently detected, escalated, and closed with a written verdict.

Wazuh TheHive Docker OpenSearch T1190 T1059.007 T1213 T1486
CASE // CIPHERVAULT-2026 Lab

CipherVault: Browser-Based Encryption Tool

A client-side encryption tool built with vanilla JavaScript and the Web Crypto API. Supports Caesar, Vigenère, Base64, RSA-2048, and SHA-256, all processed locally with no server round trip. During a self-review, found and patched a stored XSS vulnerability in the saved-messages view.

JavaScript Web Crypto API RSA-2048 Client-Side Only
CASE // NETSCAN-2026 Lab

Network Security Scanner with Firewall Rule Simulator

A real time network scanner and firewall simulator built with Flask and Nmap. Supports TCP SYN, UDP, and service version scans with live WebSocket updates. When run with admin or root privileges, deny rules aren't just visual, they execute a real netsh or iptables command scoped to that specific IP and port pair, actually dropping matching traffic at the OS level.

Flask Nmap WebSockets iptables / netsh
CASE // FYP-IEEE-2025 Research

Federated Learning IDS for IoT Healthcare

Team lead on a CNN, BiLSTM, and GRU based intrusion detection model for IoT enabled healthcare systems, 99.8% detection accuracy, Grade A evaluation. Co-authored and published in IEEE Xplore, presented at DataSciMI 2026.

CNN / BiLSTM / GRU Federated Learning IEEE Xplore
02

Experience

JAN 2026
to
JUN 2026

Threat Detection & SOC Research Intern (Cybersecurity Intern)

CNS Engineering, Lahore
  • Investigated a high severity incident correlating 14 alerts and 13 pieces of forensic evidence, tracing the attack chain to root cause via VirusTotal hash verification.
  • Executed 7 MITRE ATT&CK techniques via Atomic Red Team: 3 blocked outright by EDR, 3 detected through behavioral analysis alone.
  • Wrote KQL queries in Advanced Hunting across a 2 hour telemetry window, surfacing 5 findings mapped to 6 ATT&CK techniques.
  • Ran a phishing simulation campaign measuring a 20% credential compromise rate, with credential entry occurring in under 2 minutes of delivery.
  • Authored a 6 phase Phishing Response Playbook aligned to NIST SP 800-61.
  • Onboarded 4 endpoints to Microsoft Defender for Endpoint across GPO and Intune deployment methods.
03

Detection Coverage

SIEM & XDR

  • Microsoft Defender XDR
  • Microsoft Sentinel
  • Wazuh SIEM
  • ELK Stack
  • TheHive

Endpoint & Identity

  • Defender for Endpoint
  • Microsoft Intune
  • Active Directory
  • GPO Deployment

Query & Analysis

  • KQL
  • Log Analysis
  • Threat Hunting
  • Incident Triage

Tools & Infra

  • Docker
  • OpenSearch
  • Sysmon
  • Mythic C2
  • Linux
  • Windows Server
04

Certifications

05

Send a Message