Cybersecurity · Warsaw, Poland

Sodik
Tursunboev

Cybersecurity practitioner building at the intersection of Detection Engineering, SOC operations, SIEM, Active Directory security, Purple Teaming and offensive security.

CEH v13 · VERIFIED ↗TryHackMe Top 1%230+ LabsOfficial EC-Council TrainingMicrosoft SentinelSplunk EnterpriseWazuhELK StackMITRE ATT&CK
PROFILE / ST-01ONLINE
Sodik Tursunboev
Warsaw, PLCurrent base
UzbekistanOriginally from
DETECTION_ENGINEERING
SOC / PURPLE_TEAM
01 / ABOUT

Attack knowledge translated into defensive visibility.

I'm Sodik Tursunboev, originally from Uzbekistan and currently based in Warsaw, Poland. I build security projects that let me execute adversary techniques, observe the telemetry, create detections, investigate the behavior and measure whether the defensive control actually works. My main career direction is Detection Engineering and SOC operations, supported by hands-on offensive security and purple-team work.

Top 1%TryHackMe
230+Labs completed
CEH v13Certified Ethical Hacker
3+ yearsIndependent cybersecurity study & building
02 / PROJECTS

Built, attacked, measured and hardened.

Flagship · SIEM · SOAR · Detection Validation

Custom SIEM + Sentinel BAS

A full detection-and-response platform built from scratch in Python, paired with a Breach & Attack Simulation engine that validates whether detections actually fire against live attack simulations.

PUBLIC GITHUB REPO ↗
35Correlation-based detection rules
SigmaYAML detection engine support
70%Documented BAS run coverage: 7 detected / 3 missed
3 rolesViewer / Analyst / Admin RBAC
Detection & Response Platform

Mini SIEM

Multi-source ingestion across Windows Event Log, Linux syslog, Sysmon and remote Windows forwarders, with attack-chain correlation, case management, threat hunting, SOAR workflows and AI-assisted incident summaries.

Detection Validation Engine

Sentinel BAS

Drives Atomic Red Team techniques against the live lab, correlates resulting alerts by MITRE ATT&CK technique, host and timing, then classifies validation outcomes as Detected, Delayed or Missed.

  • Automatic multi-stage attack-chain correlation into incidents
  • Threat-hunting query language with saved hunt workflows
  • Analyst-approved SOAR actions with hard safety guardrails
  • MITRE ATT&CK tagging, heatmap, timeline and risk context
  • IOC watchlists, case evidence, assignment and resolution tracking
  • Standalone Windows executable build plus hosted deployment mode
  • Security hardening including a real stored-XSS finding and fix
  • Dependency scanning, security headers, login lockout and RBAC
Validation finding: Sentinel BAS exposed pipeline defects that normal rule review did not reveal, including missing TicketEncryptionType extraction that made the Kerberoasting rule structurally unable to fire, plus forwarder self-noise that polluted telemetry.
Local AI · Security Engineering

ARGUS

Autonomous Reconnaissance and Guardian Unified System. A fully local Windows AI/voice assistant using FastAPI, Ollama, faster-whisper, Piper TTS, a custom HUD and real hardware telemetry.

A dedicated security audit identified and fixed eight vulnerabilities including XSS-to-RCE, unauthenticated local API access, SSRF and credential disclosure.

Purple Team · Active Directory

Active Directory Security Lab

An enterprise-style AD lab for end-to-end attack-and-detection workflows including LLMNR poisoning, Kerberoasting, AS-REP Roasting, credential abuse, lateral movement, DCSync and Golden Ticket scenarios.

Linux · Operating Systems

SODIK OS

A custom bootable Arch Linux-based operating-system project built as a functional environment with system customization, security tooling and a distinct cyber-oriented interface.

Web · Education · AI

Polszczyzna & IELTS Platforms

Polszczyzna is a Polish-learning platform for Uzbek-speaking beginners. I also built four personalized IELTS-preparation apps using Next.js 14, Tailwind CSS, Supabase, Vercel and AI integrations.

03 / SOC & SKILLS

Hands-on across monitoring, detection, attack simulation and engineering.

01Microsoft SentinelSIEM / SOC monitoring, investigation and detection workflows
02Splunk EnterpriseSecurity search, telemetry analysis, dashboards and investigation workflows
03WazuhHost monitoring, security visibility, alerting and endpoint-focused analysis
04ELK StackElasticsearch, Logstash and Kibana workflows for log ingestion, search and visualization
05EDR & Endpoint DetectionEndpoint telemetry, alert triage and detection workflows across EDR-style tooling
06Sigma + SysmonPortable detection logic and high-value Windows telemetry analysis
MICROSOFT SENTINEL SPLUNK ENTERPRISE WAZUH ELK STACK EDR SIGMA SYSMON MITRE ATT&CK ATOMIC RED TEAM THREAT HUNTING MICROSOFT SENTINEL SPLUNK ENTERPRISE WAZUH ELK STACK EDR SIGMA SYSMON MITRE ATT&CK ATOMIC RED TEAM THREAT HUNTING
SOC WORKFLOW / PRACTICAL APPROACH LIVE
01ObserveTelemetry & alerts
02TriagePrioritize signal
03InvestigateContext & evidence
04DetectBuild logic
05ValidateReplay attack behavior
06ImproveClose the gap

Detection & SOC

Detection EngineeringSOC OperationsSIEMSOARThreat HuntingIncident AnalysisIOC AnalysisMTTDDetection Validation

SIEM / SOC Platforms

Microsoft SentinelSplunk EnterpriseWazuhELK StackElasticsearchLogstashKibanaEDR WorkflowsEndpoint TelemetryAlert TriageSecurity Monitoring

Threat Detection

MITRE ATT&CKSigmaSysmonAtomic Red TeamBASAttack Mapping

Offensive & AD

Penetration TestingRed TeamingActive DirectoryKerberoastingAS-REP RoastingLLMNR PoisoningDCSyncGolden TicketLateral MovementWeb Exploitation

Analysis & Response

Phishing AnalysisMalware AnalysisIOC ExtractionIncident ReportingSecurity HardeningSecurity Automation

Engineering

PythonFastAPIFlaskTkinterREST APIsWindowsLinuxArch Linux

AI & Web

Ollamafaster-whisperPiper TTSNext.js 14Tailwind CSSSupabaseVercelClaudeGroqGemini

Mobile / Lab Tooling

Kali NetHunterTermuxscrcpyMetasploitmsfvenom
04 / CREDENTIALS & TRAINING

Verified certification backed by structured training and sustained hands-on practice.

CEH
EC-COUNCIL VERIFIED

Certified Ethical Hacker — CEH v13

Certified by EC-Council, with the credential independently verifiable through the official ASPEN badge system.

StatusVerified
IssuedOctober 6, 2025
Valid throughNovember 1, 2026
Official Training

EC-Council CEH v13 Official Training

Completed the official EC-Council CEH v13 training course in addition to earning the CEH certification.

Continuous Development

Additional Cybersecurity Training

Completed numerous additional training courses and practical exercises across offensive security, SOC operations, detection engineering and security analysis.

Practical Platform

TryHackMe — Top 1%

More than 230 completed labs plus SOC, penetration-testing, red-team and defensive-security challenges.

PATH / 01Junior Penetration TesterTryHackMe learning path completed
PATH / 02Cyber Security 101TryHackMe learning path completed
PATH / 03Red TeamingTryHackMe learning path completed
PATH / 04SOC Level 1TryHackMe SOC analyst learning path completed
Training philosophy: structured learning + repeated hands-on validation. Certification, official courseware, learning paths, labs, challenges and self-built security environments.
Community / Uzbek Cybersecurity

Cybersecurity explained simply in Uzbek.

I run a Telegram channel for Uzbek-speaking readers where I share cybersecurity advice, practical guidance and security news in simple, accessible language.

Practical Profile

Labs are part of a larger engineering workflow.

I combine guided training with custom SIEM development, Active Directory attack-and-detection labs, Sentinel BAS, threat hunting, detection validation and technical write-ups.

05 / CONTACT

Let's talk security.

I'm focused on opportunities and conversations around SOC analysis, detection engineering, purple teaming, security engineering, threat hunting and Active Directory security.