Open to work

Ahmed Sajid Butt

SOC Analyst L1 | Detection Engineering | Microsoft Defender XDR

Lahore, Pakistan

Message on Bano Qabil Jobs

You’ll be asked to sign in

About

I'm a Computer Science graduate (Bahria University Lahore, 2025) focused on Security Operations: SOC monitoring, threat detection, and incident response.

Most recently, I worked on Threat Detection and SOC Research at CNS Engineering, where I ran hands on Microsoft Defender XDR work: MITRE ATT&CK mapped attack simulations, KQL threat hunting in Advanced Hunting, a full ransomware investigation traced end to end, and Defender for Endpoint onboarding across GPO and Intune. I authored formal deliverables including a Threat Hunt Report, Incident Forensics Report, and Ransomware Investigation Runbook.

To keep building hands on skills between roles, I built Vigil, a self hosted SOC detection lab where I wrote custom Wazuh detection rules from scratch (signature based and frequency correlation), simulated a full four stage attack chain mapped to MITRE ATT&CK, and built a working Wazuh to TheHive integration so detected alerts automatically escalate into a case management workflow. Full writeup and detection logic documented on GitHub.

I also hold KC7 Security Analyst I and Security Analyst II certifications and built Sentinel Forge, an earlier detection lab on ELK Stack with custom Kib

Skills

added by Ahmed

Experience

  1. Threat Detection & SOC Research Intern (Cybersecurity Intern)

    CNS Engineering

    2026 — 2026

Years only. The record has no months, so we never invent “Jan 2024”.

Education

  1. Bahria University Lahore Campus

    Graduated 2025