Summary
Overview
Work History
Education
Skills
Languages
Disclaimer
Timeline
Generic

Suresh Paka

Marcoola,QLD

Summary

Overall, I hold 4+ years of experience into Information Technology as Security Analyst (SOC). Moreover, I acquire good understanding of security solutions like Anti-virus, DLP, Proxy, Firewall filtering/monitoring, IPS, Phishing Emails, Email Security, Endpoint Security, Threat Hunting

Overview

6
6
years of professional experience

Work History

UnitedLex Pvt Ltd
09.2021 - Current
  • Monitoring the customer network using SIEM tool–Splunk, Crowd strike, MS Azure, MS defender, MCAS.
  • Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources.
  • Performing Host activity analysis on Crowd strike. Analyzing the suspicious behaviors of Hosts and servers from Crowd strike Console.
  • Isolate the systems in Crowd strike in compromised scenarios.
  • Monitor the detections and Incidents console in Crowd strike.
  • Check the file behavior analysis and also check files available on the host by connecting to the Host in Crowd strike.
  • Fine tune the alerts and place IOC exceptions and IOA exceptions for required Host groups in Crowd strike.
  • Worked on different Endpoint Alerts with respect to Mitre Framework.
  • Monitor the alerts in Microsoft defender for cloud.
  • Worked on Azure IPC alerts, MCAS alerts.
  • Monitor alerts in Microsoft security center and take appropriate action.
  • Analyzing the Phishing emails forwarded to SOC mail box and respond to the users with appropriate template.
  • Used Proof point and MS defender for O365 to verify and understand the behavior of emails routing within the organization.
  • Block IOCs identified from TruStar TI and Phishing emails
  • Analyzing suspicious commands and executions in CS alerts
  • Performed Threat Hunting of New CVE
  • Creating of New use cases (Notables) in Splunk and test and implement in Production.
  • Creating Lookups, Dashboards to store the required data in Splunk.
  • Working on Fine tuning the alerts in Splunk, MCAS alerts to reduce False Positives.
  • Worked on TI reports and add them to the Security Controls.
  • Resetting the user’s password and revoke sessions in Azure AD in case of Compromised accounts.
  • Delete the suspicious files on users Machine detected by Crowd strike and MS defender.
  • Worked on different cloud Anomaly alerts.
  • Created Use cases in Splunk.
  • Updating Agents of Security controls using SCCM
  • Working with Blue Teams & Red Teams in Organization and preventing from new attacks.

Wipro
03.2020 - 06.2021
  • Monitoring the customer network using SIEM tool–Splunk and Service Now
  • Performing Real-Time Monitoring, Investigation, Analysis, Reporting and Escalations of Security Events from Multiple log sources.
  • Performing Malware and Email Analysis.
  • Analyzing suspicious behaviors (using virustotal.com, ipvoid.com).
  • Raising ticket to my higher officials in Ticketing tool. (JIRA)
  • Analyzing of email phishing attack using various open-source tools such as MXToolbox, redirectdetective.com.
  • Escalating the security incidents based on the client's SLA and providing meaningful information related to security incidents by doing in-depth analysis of event payload, providing recommendations
  • Analyzing FOA Accounts.
  • Analyzing Scam calls, emails, SMS reported by Customer
  • Preparing Reports based on Traffic.
  • Initial troubleshooting with respect to Log Source Communication issues.
  • Creating Reports alerts and investigate issues identified during monitoring the live traffic.
  • Handling multiple customers globally analyzing the customer networks for potential security attacks.
  • Working with the Endpoint security.
  • Displaying the event data in different layouts by defining Dash Boards & Data Monitors.
  • Whitelisting of IP’s and Blocking the IP’s if required

Education

Bachelor of Science - undefined

Osmania University
Hyderabad
01.2019

Skills

  • SIEM Tool: Splunk, Qradar, SentinalOne,Rapid7
  • Ticketing tool: Service Now, JIRA
  • EDR : MS defender, Crowd Strike Falcon, DLP : Proofpoint,
  • Email Security: ProofPoint and MS Defender
  • Cloud: MS Azure
  • Open sources: MX toolbox, Hybrid analysis, virus total, Abuse IPDB, URL Scan and Void
  • Sandbox: Crowdstrike, Proofpoint isolation browser, Lambdascanner

Languages

English
Full Professional

Disclaimer

I Suresh Paka declare that the above given information is correct to the best of my knowledge and belief.

Timeline

UnitedLex Pvt Ltd
09.2021 - Current

Wipro
03.2020 - 06.2021

Bachelor of Science - undefined

Osmania University
Suresh Paka