I am a dedicated Cyber Security student with a strong focus on Blue Team operations, Security Operations (SOC), and Network Defense. My technical journey is centered on building resilient systems and mastering the defensive side of cybersecurity.
My training covers the entire spectrum of security operations, from low-level system hardening to cloud security and incident response:
- Operating Systems & Hardening:
- Windows: Architecture, AD/GPO configuration, PowerShell automation, Registry, and system-level security (BitLocker, AppLocker, Credential Dumping mitigation).
- Linux: System administration, file system management, advanced permission handling (rwx), and security hardening (UFW/iptables).
- Networking & Protocol Analysis:
- Deep understanding of OSI/TCP/IP layers, routing, switching, and transport protocols.
- Hands-on experience with network devices (Firewalls, NGFW, IDS/IPS), Wireshark packet inspection, and traffic analysis.
- Security Operations (SOC) & SIEM:
- SIEM implementation and log management (Wazuh, Splunk).
- Log parsing, normalization, and correlation using Regex.
- SOAR fundamentals and building automated incident response playbooks using Python.
- Vulnerability & Risk Management:
- Vulnerability assessment using OpenVAS and Nessus, CVSS scoring, and patch management strategies.
- Understanding GRC frameworks (ISO 27001, NIST CSF) and data privacy compliance.
- Digital Forensics & Incident Response:
- Forensic workflow, chain of custody, and memory dump analysis (Volatility, Autopsy).
- Execution of the Incident Response lifecycle, from triage to recovery, and threat hunting.
- Cloud & Application Security:
- Cloud security principles (AWS/Azure), IAM, and Cloud EDR.
- Web Application Security (OWASP Top 10), Burp Suite testing, and email layer security (SPF/DKIM/DMARC).
- Cisco Networking Academy: Introduction to Cybersecurity
- Cisco Networking Academy: Network Defense
I actively translate theoretical knowledge into practice through:
- Network Security Labs: Configuring NGFW, performing Layer 2 attack simulations, and troubleshooting DHCP/ARP poisoning.
- Malware Analysis: Detonation and sandboxing concepts, static/dynamic analysis of threats.
- Adversary Emulation: Using Atomic Red Team to test detection capabilities via SIEM.
I am always eager to engage with the security community, share knowledge, and discuss future collaborations.
- LinkedIn: Umid Guluzada
“Cybersecurity is not a final product, but a continuous process.”