Skip to content

Syed Jawad

Security Engineer

Transforming noise into high-fidelity threat detection.

Wazuh setup, detection engineering, and alert automation with n8n, DFIR-IRIS, TheHive, Slack and Jira, scoped, validated and documented.

WAZUH LAB · HEALTHYevents 0

    MITRE ATT&CK coverage

    T1059.001T1003.001T1098T1548

    Illustrative lab simulation, not real incident data.

    Live SOC simulation

    Watch an alert move through the pipeline.

    Pick an attack below and replay it end to end: the endpoint logs it, Wazuh detects it, n8n or Shuffle automates the response, threat intel enriches it, DFIR-IRIS or TheHive opens a case, and Slack or Jira notifies the team.

    SOC / INCIDENT REPLAY · idle
    1. 01 / Endpoint

      Sysmon · Auditd · AWS

      waiting

    2. 02 / Detect

      Wazuh SIEM

      waiting

    3. 03 / Automate

      n8n / Shuffle

      waiting

    4. 04 / Enrich

      OpenCTI · Cortex

      waiting

    5. 05 / Case

      DFIR-IRIS · TheHive

      waiting

    6. 06 / Notify

      Slack · Jira

      waiting

    $ replay --scenario ransom --mitre T1486

    Press “Run replay” to stream the workflow.

    DFIR-IRIS case

    pending

    Case appears once the alert is enriched.

    Slack · #soc

    pending

    Analyst notification follows case creation.

    stages 0/6MITRE T1486replays this visit 0

    Illustrative simulation of the open-source SOC workflow pattern, not a real incident or customer data.

    Tools & ecosystem

    The stack I work with every day.

    Open-source and cloud tools, grouped by the job they do in a SOC.

    SIEM & Analytics

    WazuhSplunkIBM QRadarMicrosoft SentinelELK / ElasticOpenSearchKafkaGrafanaDatadog

    EDR, NDR & Endpoint

    CrowdStrikeSysmonAuditdSuricataYARAVIPREWazuh FIM / SCA

    DLP, Network & Monitoring

    Symantec DLPCloudflareSolarWindsSIRP

    SOAR & Automation

    n8nShufflePythonAnsibleMCP

    Case Management & Ticketing

    DFIR-IRISTheHiveJiraosTicketSimpleRisk

    Threat Intel

    VirusTotalAbuseIPDBOpenCTICortexCDB ListsMITRE ATT&CK

    Cloud & Infrastructure as Code

    AWS CloudTrailAWS GuardDutyAWS EC2AzureTerraform

    Notify & Platforms

    SlackEmailLinuxWindows

    Experience

    Security operations, architecture and training.

    Roles spanning live SOC environments, Wazuh architecture and hands-on training, listed from current to earliest.

    Current roleOct 2025 to Present

    Ebryx (Pvt.) Ltd.

    Security Engineer

    Onsite

    • Monitor, triage, and investigate alerts across Splunk, IBM QRadar, Wazuh, ELK, Symantec DLP, SIRP, VIPRE, Cloudflare, CrowdStrike, SolarWinds, and Microsoft Sentinel.
    • Alert investigation, log analysis, event correlation, severity assessment, and root-cause analysis.
    • Fine-tune detection rules, investigate false positives, and improve incident response workflows.
    • Test AI-assisted security analysis and triage against analyst findings with structured feedback.

    Tools used

    SplunkIBM QRadarWazuhELKSymantec DLPSIRPVIPRECloudflareCrowdStrikeSolarWindsMicrosoft Sentinel
    Ambassador · CommunityJun 2025 to Present

    Wazuh

    Wazuh Ambassador

    Remote

    • Develop and test SOC use cases, custom detection rules, integrations, and investigation workflows.
    • Test and evaluate Wazuh AI-powered triage (Mobius) against real analyst reasoning.
    • Support the Wazuh community and run webinars, demos, and technical sessions.

    Tools used

    WazuhMobius AI triagen8nSlack
    Trainer · EducationJun 2025 to Present

    WazuGuardix

    Wazuh Trainer

    Remote

    • Hands-on Wazuh training: deployment, architecture, agents, FIM, SCA, and vulnerability detection.
    • Train on custom decoders, detection rules, alert tuning, and use-case development.
    • Labs on integrations, OpenSearch, dashboards, SIEM troubleshooting, and security automation.

    Tools used

    WazuhOpenSearchFIMSCA
    Foundational · ArchitectureJun 2024 to Oct 2025

    ITFortress

    Wazuh Architecture Trainee

    Remote

    • Designed, deployed, and maintained Wazuh Manager, Indexer, Dashboard, and agent infrastructure.
    • Tuned agents, FIM, SCA, and vulnerability detection across Linux and Windows.
    • Built custom XML decoders, detection rules, and log parsers; integrated AWS CloudTrail into Wazuh.

    Tools used

    WazuhAWS CloudTrailLinuxWindows
    Download full resume

    Featured architecture labs

    Real builds you can inspect.

    Each lab shows the problem, how it was built, and public proof.

    Syed Jawad Ali Shah

    Security Engineer · Platinum Wazuh Ambassador

    Let's talk

    Tell me what your SOC should do better.

    Wazuh setup or review, log sources, detection tuning, alert automation, or team training.

    Confidential · Defined scope before any work starts

    Can you work with an existing setup?

    Yes. Existing configurations can be reviewed and scoped first, and changes are agreed before anything is touched.

    How is pricing determined?

    It depends on the platform, integrations, environment, and deliverables. Commercial terms are agreed before work begins.

    What should I share initially?

    Platform names, an approximate endpoint or log-source count if you know it, and a short description of the challenge. Please don't share credentials, sensitive logs, or access details at this stage.

    What happens after I contact you?

    We first clarify the requirement and whether an engagement is a good fit, then agree on a sensible next step.

    Can you tailor a session?

    Yes. Audience, topic, format, and learning objectives are agreed before the session.

    Message builder

    Sends straight to Syed on WhatsApp or email.

    Please don't include credentials, sensitive logs, or access details.