I will soc analyst threat hunting and blue team tasks
Threat Hunting, Vulnerability Audits and Security Reports
About this Gig
Need a dedicated analyst to handle your blue team operations? I provide remote defensive security tasks, active monitoring, and threat detection to keep your infrastructure secure. With deep experience in SOC environments, SIEM analysis, and EDR monitoring, I analyze your network and system activity to identify and neutralize threats.
WHAT I DO (BLUE TEAM SERVICES)
- SOC Monitoring: Actively analyzing alerts, logs, and EDR events for anomalies.
- Threat Hunting: Proactively searching systems for active threat vectors or IOCs.
- Detection Engineering: Creating custom Yara, Sigma, and KQL alert rules.
- Incident Analysis: Investigating alerts and drafting containment/mitigation reports.
- Log Assessment: Auditing log parsing, normalization, and alert flows.
I deliver comprehensive, manually verified security reports and threat incident timelines.
PLEASE MESSAGE ME BEFORE ORDERING to align on your scope.
My Portfolio
Other Support & IT Services I Offer
FAQ
What data or logs do you need to perform a threat hunt?
will need you to export and share your system logs, SIEM events, EDR alerts, firewall logs, or network PCAP captures. Standard formats like JSON, CSV, EVTX (Windows Event Logs), or raw log files work best.
Do you perform active incident containment or just reporting?
The standard service covers active threat detection, analysis, and actionable reporting (with clear remediation roadmaps). If you require active isolation or containment tasks, please message me to discuss system access and custom authorization.
Can you write custom alert rules for my specific security tools?
Yes. I can design and engineer custom Yara rules, Sigma rules, and KQL queries tailored to your specific SIEM/EDR configurations to help automate detection of similar threats in the future.
How do you structure and map your threat hunting findings?
I map all identified threats and suspicious behaviors directly to the MITRE ATT&CK framework. This helps you understand exactly which tactics, techniques, and procedures (TTPs) were attempted or executed.

