Ahmed Sajid Butt
SOC Analyst L1 | Detection Engineering | Microsoft Defender XDR
Lahore, Pakistan
You’ll be asked to sign in
About
I'm a Computer Science graduate (Bahria University Lahore, 2025) focused on Security Operations: SOC monitoring, threat detection, and incident response.
Most recently, I worked on Threat Detection and SOC Research at CNS Engineering, where I ran hands on Microsoft Defender XDR work: MITRE ATT&CK mapped attack simulations, KQL threat hunting in Advanced Hunting, a full ransomware investigation traced end to end, and Defender for Endpoint onboarding across GPO and Intune. I authored formal deliverables including a Threat Hunt Report, Incident Forensics Report, and Ransomware Investigation Runbook.
To keep building hands on skills between roles, I built Vigil, a self hosted SOC detection lab where I wrote custom Wazuh detection rules from scratch (signature based and frequency correlation), simulated a full four stage attack chain mapped to MITRE ATT&CK, and built a working Wazuh to TheHive integration so detected alerts automatically escalate into a case management workflow. Full writeup and detection logic documented on GitHub.
I also hold KC7 Security Analyst I and Security Analyst II certifications and built Sentinel Forge, an earlier detection lab on ELK Stack with custom Kib
Skills
added by Ahmed- Microsoft Defender XDR
- Microsoft Defender for Endpoint (MDE)
- Endpoint Security Administration
- Microsoft Sentinel (SIEM)
- Kusto Query Language (KQL)
- Wazuh SIEM
- TheHive Case Management
- ELK Stack (Elasticsearch, Logstash, Kibana)
- OpenSearch
- Sysmon
- Log Analysis
- Incident Triage
- Threat Hunting
- Active Directory
- Microsoft Intune
- Docker
- Mythic C2
- Linux (Ubuntu, Kali Linux)
- Windows Server
Experience
Threat Detection & SOC Research Intern (Cybersecurity Intern)
CNS Engineering
2026 — 2026
Years only. The record has no months, so we never invent “Jan 2024”.
Education
Bahria University Lahore Campus
Graduated 2025
