Enterprise Azure SOC: Wazuh SIEM, SOAR & Incident Response Lab
Built a three-system enterprise SOC environment in Microsoft Azure integrating Active Directory, Wazuh SIEM, endpoint telemetry, detection engineering, threat hunting, Python reporting, and Shuffle SOAR. Processed 482 alerts, investigated authentication attacks, enriched incidents with threat intelligence, enforced analyst approval, executed controlled response actions, and validated results on the affected endpoint.