Results-driven IT Specialist with a proven track record at Senior Aerospace SSP, excelling in vulnerability management and email security. Skilled in Active Directory and VPN administration, I enhance system integrity while delivering exceptional technical support. My proactive approach and strong time management skills ensure optimal performance and security across all IT operations.
Elastic Stack SIEM Configuration And Management, Successfully implemented and configured Elastic SIEM in a home lab environment., Set up a Kali Linux virtual machine using VirtualBox, and installed an agent on the Linux machine to forward logs and telemetry to the Elastic SIEM., Created a custom alert query targeting all events with the action 'nmap_scan' designed to detect any variation of an Nmap scan performed on the endpoint., Configured alerts with a 'High Severity' classification, and set the alert action to automatically generate incident tickets in Jira.
Nessus Vulnerability Scan
Successfully set up and scanned my Windows 11 VM using Nessus. To ensure connectivity for
the scan, I initially disabled the firewall on the VM using the Windows Firewall Management
Console (wf.msc).
The primary goal was to perform a credentialed scan of the VM. To prepare for this, I enabled
the “Remote Registry”service, allowing the scanner to access the registry and identify potential
misconfigurations. Additionally, I turned on network discovery and enabled file and printer
sharing to facilitate seamless communication between Nessus and the target system.
In the Nessus configuration, I specified the target VMs IP address along with a valid
administrative username and password. Performing a credentialed scan provided deeper
access to the system, enabling the identification of vulnerabilities that could be exploited by
users with elevated privileges, such as insider threats.