Junior SOC Analyst, Kraków
I studied cybersecurity and now I mostly work on detection: writing Sigma rules for Windows and checking them against real attack logs to see what they actually catch and what they miss.
Looking for my first job in a SOC or IT support team, in Kraków or remote. I have the right to work in Poland.
github.com/flexeykinDev/soc-detection-lab
Three Sigma rules tested on 278 real EVTX attack captures from a public dataset. They fired 17 times across 15 captures, including mimikatz, Meterpreter and MalSeclogon.
A few things I learned along the way:
- The LSASS rule looks at process access masks instead of file names, so it still works when a tool is renamed.
- I converted the rules to Splunk SPL and to KQL for Defender XDR. One of them didn't convert to KQL, and the README explains why.
- My first PowerShell rule had false positives on the remoting host. I narrowed it down and kept the real attacks.
Side projects I built with AI help. I made the decisions, tested and fixed them, and got them working.
| QuasarMC | Minecraft server core written from scratch in Java |
| dbd-perk-randomizer | Perk randomizer for Dead by Daylight, data updates itself with GitHub Actions |
| roflo-pinterest | Small Python tray app, packaged as an .exe |
| lumen | Music widget for the Windows 11 taskbar, in Rust |
| Vortex-Hub | My personal site |
Ukrainian and Russian are my native languages, English is B2, and I'm learning Polish (A2).