Portfolio Projects Playbooks Blog Reports Contact

U.S. Army Veteran · Security Operations

Brandon Love SOC Analyst | Incident Response | Detection Engineering

I am a U.S. Army Staff Sergeant with 12 years of leadership experience and hands-on cybersecurity experience building SIEM environments, investigating incidents, analyzing endpoint and network evidence, automating workflows, and developing practical security tools.

Microsoft Sentinel Microsoft Defender Wazuh KQL Python PowerShell DFIR Network Forensics MITRE ATT&CK Azure

Portfolio Highlights

Original tools and investigation work that demonstrate job-ready skills.

PCAP Quick Profiler

Automated network triage that converts packet captures into analyst-ready findings.

Extracts protocol activity, hosts, HTTP data, TLS indicators, and other useful evidence to accelerate initial network investigations.

Python PyShark TShark Network Forensics
View case study →

Windows Log Triage

Python-based EVTX and Sysmon analysis with IOC extraction and suspicious behavior detection.

Produces HTML, JSON, and CSV outputs while identifying behaviors such as encoded PowerShell, LOLBins, suspicious process chains, and common attacker techniques.

Python EVTX Sysmon IOC Extraction
View case study →

SOC Playbooks

How I triage, investigate, document, and respond to security alerts.

Suspicious PowerShell Execution

Event IDs 4104, 4688, Sysmon 1, 3, 7, and 11

Investigates encoded commands, suspicious parent-child relationships, downloaded payloads, persistence activity, and related network connections.

SharePoint Privilege Escalation

Public-facing application activity and account impact

Reviews IIS and SharePoint evidence, authentication changes, uploaded files, privilege modifications, webshell indicators, containment, and patch status.

Malicious Office Document

Phishing, macro execution, scripting engines, and LOLBins

Correlates the message source, attachment, Office child processes, dropped files, network traffic, user impact, and recommended containment actions.

Military Leadership Applied to Cybersecurity

Operational experience that strengthens security analysis and incident response.

I bring 12 years of U.S. Army experience, including two deployments and leadership responsibilities as a Staff Sergeant, Platoon Sergeant, Operations NCO, and Battle Desk NCOIC.

  • Make time-sensitive decisions with incomplete information
  • Prioritize incidents according to risk and mission impact
  • Communicate clearly across technical and nontechnical teams
  • Train and lead personnel under operational pressure
  • Maintain documentation, accountability, and procedural discipline
  • Coordinate response activities across multiple stakeholders

Latest Technical Writing

Incident investigations, SOC analysis, lessons learned, and security research.

Explore the full archive

Browse all technical articles, reports, and investigations.

View All Posts →

Get in Touch

Open to cybersecurity opportunities, professional networking, and collaboration.