Skip to content
View albertobayan's full-sized avatar

Block or report albertobayan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
albertobayan/README.md

Hi, I'm Alberto Bayán 👋

Junior SOC Analyst with a background in IT Support, Systems Administration and Networking.

I currently work in a Security Operations Centre, investigating and triaging security incidents, analysing indicators of compromise and supporting incident management and response activities.

My main interests are Blue Team operations, threat detection, incident response and security automation.

🛡️ Cybersecurity

  • Security incident investigation and triage
  • EDR / XDR analysis
  • IOC analysis: IPs, domains, hashes, files and processes
  • Threat intelligence and reputation analysis
  • Incident management and escalation
  • Security monitoring and event analysis
  • Authorised containment and remediation support

🔧 Technologies & Tools

Security

  • Microsoft Defender for Endpoint
  • CrowdStrike
  • Palo Alto Cortex XDR
  • Threat Intelligence platforms
  • Jira

Systems & Infrastructure

  • Windows Server & Active Directory
  • Microsoft 365
  • Microsoft Entra ID
  • Microsoft Intune
  • Windows & Linux
  • TCP/IP, DNS, DHCP, VLANs and VPNs
  • Ubiquiti UniFi
  • Freshservice
  • SharePoint

📂 Featured Projects

Python-based SOC automation platform for threat detection, IOC analysis, log monitoring, threat intelligence and incident response workflows.

  • IOC detection and classification
  • Security event parsing
  • Log ingestion and monitoring
  • Threat intelligence enrichment
  • Detection and response automation
  • SOC / SOAR-oriented architecture

Containerized operations and security platform for incident management, access auditing and monitoring.

  • FastAPI, PostgreSQL, Docker and Nginx
  • JWT authentication and role-based access control
  • Prometheus and Grafana monitoring
  • Security event logging and audit trails

Windows Server and Active Directory home lab simulating a small business infrastructure.

  • Active Directory, DNS and DHCP
  • Users, groups and Organizational Units
  • NTFS permissions and Group Policies
  • Security auditing
  • PowerShell automation
  • Jira Service Management

High-availability infrastructure project.

  • MariaDB Galera Cluster
  • HAProxy load balancing
  • Keepalived failover
  • VPN access
  • Security monitoring
  • Automated backups

🎓 Certifications

  • Microsoft Azure Fundamentals (AZ-900)
  • Cisco CCNA 1-3
  • Blue Team Level 1 (BTL1) — In Progress
  • Cambridge English C1 Advanced

🌐 Website

🌍 Languages

  • Spanish — Native
  • English — C1
  • Japanese — JLPT N5 in progress

📫 Contact

Pinned Loading

  1. sentinelflow sentinelflow Public

    Python-based SOC automation platform for threat detection, IOC analysis, log monitoring, threat intelligence and incident response workflows.

    Python 1

  2. TFG-Cluster-HA TFG-Cluster-HA Public

    ClusterX is a high-availability infrastructure project with a MariaDB Galera cluster, HAProxy load balancing, Keepalived failover, VPN access, security monitoring and automated backups.

    PHP 1

  3. windows-server-jira-helpdesk-lab windows-server-jira-helpdesk-lab Public

    Windows Server home lab featuring Active Directory, DNS, DHCP, NTFS permissions, Group Policy, security auditing, PowerShell automation and Jira Service Management.

    PowerShell 1

  4. OpsGuard-Cloud OpsGuard-Cloud Public

    OpsGuard Cloud is a containerized operations platform for incident management, audit logging, security event tracking and monitoring. Built with FastAPI, PostgreSQL, Nginx, Prometheus and Grafana, …

    Python