Cybersecurity portfolio

Kirolos Khairy

Junior SOC Analyst L1

Information Security graduate from Ural Federal University, focused on SOC operations, security event and log analysis, web security, and DFIR. Building practical experience through security projects, labs, and competitions.

SOC & Incident Analysis Security events and logs, initial triage, MITRE ATT&CK, and Cyber Kill Chain.
Web Security OWASP Testing Guide / CWE, Burp Suite, and vulnerability analysis.
DFIR Windows artifact collection, integrity verification, case management, and the TRACE project.

About

Information Security Specialist — Focus on SOC, Web Security & DFIR

I am an Information Security graduate from Ural Federal University with a focus on SOC operations, security event and log analysis, initial incident triage, web security, and digital forensics.

My practical experience includes web application security assessment using the OWASP Testing Guide, vulnerability classification with OWASP / CWE, Burp Suite work, and analysis of security events and logs in laboratory environments.

I also developed TRACE as my graduation project: a DFIR workstation for collecting, importing, and analyzing Windows digital artifacts, with integrity verification, case management, audit logging, and report generation.

Skills

Technical areas

Focused on the technologies and security practices reflected in my current CV and practical work.

SOC & Incident Analysis

Security event and log analysis, initial incident triage, MITRE ATT&CK, and Cyber Kill Chain fundamentals.

Triage MITRE ATT&CK Cyber Kill Chain

SIEM & Monitoring

Wazuh and ELK Stack for event search, parsing, normalization, and security monitoring; basic IDS/IPS concepts.

Wazuh ELK Stack IDS/IPS

Web Security

OWASP Testing Guide, OWASP / CWE, Burp Suite, web vulnerability analysis, and controlled security testing.

OWASP Burp Suite Web Security

DFIR & Windows Artifacts

Collection and analysis of Windows digital artifacts, SHA-256 integrity checks, case management, and audit logging.

DFIR Windows Artifacts SHA-256

Programming & Automation

Python for automation and data/log processing.

Python

Operating Systems & Tools

Linux environments including Kali, Ubuntu, Astra, and CentOS, with practical work using Nessus, Cowrie, and Git.

Linux Nessus Cowrie Git

Experience

Information Security Practice

Practical training completed

Web Application Security

Assessed a training web application using the OWASP Testing Guide, documented vulnerabilities, classified findings using OWASP / CWE, and prepared remediation recommendations.

Burp Suite Extension

Developed and tested an AES Traffic Decryptor extension for Burp Suite in Java to analyze protected API traffic using AES-CBC.

Security Automation

Implemented a Python tool for automated collection and structuring of open data using Playwright and APScheduler.

Security Analysis & Documentation

Analyzed a controlled injection CTF scenario, documented the investigation process and technical findings, and developed practical documentation for security work.

Projects

Security projects

Projects that demonstrate practical work with incident investigation, digital artifacts, monitoring, and security tooling.

TRACE — DFIR Workstation

Graduation project for incident investigation: collection, import, and analysis of Windows digital artifacts, integrity verification, case management, audit logging, and HTML/PDF reporting.

C# .NET 8 WinForms DFIR

Cowrie Honeypot Monitoring

Worked with an isolated Cowrie honeypot environment to monitor attacker traffic, review logs and suspicious activity indicators, and perform initial event triage.

Cowrie Logs Triage

Competitions

Cybersecurity competitions & events

Participation in cybersecurity competitions, hackathons, and professional information security events.

UralCTF

Participation in a practical cybersecurity CTF environment focused on solving security challenges.

AlfaCTF

Participation in cybersecurity challenges requiring analysis, practical problem-solving, and teamwork.

Cyberbitva

Participation in a cybersecurity competition and related technical challenges.

IX Cup of CTF Russia

Participation in a national CTF competition in a team environment.

T1 Hackathon

Participation in a cybersecurity-focused hackathon and web security challenge.

KOD IB & UrFU Cybersecurity Events

Volunteer at the KOD IB information security conference in Yekaterinburg and participant in UrFU cybersecurity training activities.

Ural Federal University campus building

Ural Federal University, Institute of Radioelectronics and Information Technologies.

Education

Ural Federal University

Bachelor's degree in Information Security (10.03.01), 2022–2026.

Graduated from the Information Security program at Ural Federal University. My graduation thesis focused on an automated workstation for information security incident investigations.

Thesis: “Automated workstation for conducting information security incident investigations” — development of the TRACE prototype for collecting and analyzing Windows digital artifacts in DFIR tasks.

Languages

Language skills

Arabic

Native language.

Russian

B2 — working proficiency.

English

B1 — working proficiency.

Activities

Professional & community activities

Buddy System — UrFU

Mentor supporting international students with university procedures, communication, and initial adaptation.

KOD IB

Volunteer at an information security conference in Yekaterinburg and active participant in cybersecurity events.

Contact

Reach me directly

For portfolio questions, project discussion, or professional opportunities, email is the most reliable contact method.