whoislsam Available to connect
01
Security engineering / Based in Sri LankaWork footprint — Sri Lanka · Australia · United States · Germany

LAKSHANSAMEER

Abstract black chrome cybernetic figure dissolving into orange data particles

I engineer calm inside digital chaos—turning threat signals into resilient defenses.

SOC Analyst
& Security EngineerPublic identity: Lakshan Sameer · Legal name: Lakshan Sameera
Scroll to investigate
// My operating principle

SECURITY THAT SEES
BEFORE IT REACTS.

I build detection and response systems that make complex threats legible, actionable and hard to repeat.

From Microsoft Sentinel and Defender XDR to identity investigations, SIEM engineering and incident response, my work connects technical depth with evidence-led decisions.

Portrait of Lakshan Sameer
THE HUMAN BEHIND THE SIGNAL

Lakshan Sameer

Security is technical. Trust is human. I bring both to every investigation, engineering decision and client conversation.

Public identity — Lakshan Sameer
Legal name — Lakshan Sameera
0+Years of
experience
0+Projects
completed
0+Professional
certifications
2%TryHackMe
global rank
// SOC analyst arsenal

Built from live MSSP and MXDR operations—not a keyword list.

FROM SIGNAL
TO DECISION.

SOC / ACTIVE OPERATIONSWHOISLSAM
01

Alert Triage & Investigation

End-to-end validation, attack timelines, evidence capture, escalation and shift handover.

LIVE
02

Identity Threat Detection

Password spray, impossible travel, suspicious sign-ins, Entra ID and Microsoft 365 telemetry.

CORE
03

Detection & SOAR Engineering

KQL/SPL rules mapped to MITRE ATT&CK, tuning, phishing and brute-force playbooks.

BUILD
04

MSSP Operations

Multi-tenant monitoring, SLA-led incident lifecycle, client summaries and remediation guidance.

24×7
Microsoft SentinelDefender XDRSplunkAdluminLog360FortiSIEMCrowdStrikeEntra IDGuardDutyWazuhSnortMITRE ATT&CK
// Evidence-backed public threat intelligence

Every marker is derived from a named feed. No random routes, inflated counters or simulated incidents.

OBSERVED THREAT
ACTIVITY.

GLOBAL THREAT OBSERVATORYPUBLIC CTI / SOURCE VERIFIEDCOLOMBO · 06.9271° N
CONNECTING TO SOURCESSYNCING FEEDS…
LS
GLOBAL SENSOR VIEW / LAST 72 HOURSSANS ISC · DSHIELD OBSERVATIONS
VERIFYING SOURCERAW FEED ↗
01 INGESTPUBLIC FEEDS 02 VERIFYSOURCE + TIME 03 NORMALIZENETWORK + GEO 04 VISUALIZEOBSERVED ONLY
SENSOR MATRIXCOUNTRY CENTROIDSNO INFERRED ROUTES
Observed malicious source networks by country Country-level markers represent current DShield top attacking network records. Marker size represents reported target count.
SELECT A SOURCE REGIONWaiting for verified records…No route is drawn unless a source provides both endpoints.
VERIFIED SIGNAL STREAM

AWAITING SOURCE RECORDS

01OBSERVED NETBLOCKSDShield top list
02REPORTING TARGETSSum of feed records
03SOURCE COUNTRIESCountry-coded records
04FEED TIMESTAMPAwaiting source
WHAT THIS MAP MEANS

DShield aggregates reports from distributed intrusion-detection and honeypot sensors. The points show source countries for its top attacking /24 networks; they do not claim to represent every cyberattack worldwide. Locations are country centroids because the public feed supplies a country code—not precise device coordinates.

READ DSHIELD METHODOLOGY ↗
F
BOTNET C2 VERIFICATION

abuse.ch Feodo Tracker

Checking the provider’s recommended C2 feed…

Connecting to abuse.ch…
OFFICIAL DATASET ↗
ACTIVELY EXPLOITED

CISA KEV Feed

OFFICIAL SOURCE ↗
Connecting to CISA KEV…
CURRENT CYBER NEWS

Threat Headlines

THE HACKER NEWS ↗
Connecting to news feed…
OFFICIAL MICROSOFT SECURITY INTELLIGENCE

Microsoft Security Watch

Threat research and defensive updates prioritized for Sentinel, Azure, Defender and Entra.

CONNECTING TO OFFICIAL FEED
Retrieving Microsoft Security Blog…
// Connected capability graph

Select a capability to reveal its operational relationships.

THE SECURITY
CONSTELLATION.

SELECT NODE

Operational knowledge, connected.

Every capability maps to real experience, tools and delivered projects.

// Core systems & capabilities

Protecting modern environments through engineered visibility, precise investigation and response.

DEFENSE BUILT FOR
THE REAL WORLD.

01

Detection Engineering

KQL analytics, correlation logic and tuned detection across Microsoft Sentinel and Defender XDR.

02

SOC Operations

Alert triage, incident investigation, attack timelines and evidence-based escalation.

03

Cloud & Identity

Authentication anomaly analysis, account compromise validation and cloud attack-path investigation.

04

Security Research

Threat analysis, adversary behavior, vulnerability assessment and practical defensive guidance.

// Verified learning & professional credentials

A searchable record of certifications and earned badges across security operations, cloud, networking and threat analysis.

PROOF BEHIND
THE PRACTICE.

LOADING CREDENTIAL REGISTER…
VERIFIED PROFILE ↗
RETRIEVING VERIFIED RECORDS…
ISSUERS / MICROSOFT · CISCO · IBM · GOOGLE · FORTINET · ISC2
// Selected operations

A living archive of builds, research and security experiments.

WORK FROM THE
FRONT LINE.

PROJECT ARCHIVE / ONLINEEXPLORE OPERATIONS
--DOCUMENTED
OPERATIONS
--SECURITY
DOMAINS
----LATEST
DEPLOYMENT
SOC / DETECTIONCLOUD DEFENSETHREAT INTELAI SECURITY
ACTIVE STACK

AWS MICROSOFT SENTINEL SPLUNK KQL WAZUH GUARDDUTY MITRE ATT&CK PYTHON SOAR THREAT INTELLIGENCE AWS MICROSOFT SENTINEL SPLUNK KQL WAZUH GUARDDUTY MITRE ATT&CK PYTHON SOAR THREAT INTELLIGENCE

LOADING OPERATION FILES…
// Research, write-ups & field notes

Practical security research—from exploit reproduction and SOC engineering to threat-intelligence pipelines.

THINKING
IN PUBLIC.

CONNECTING TO MEDIUM RSS…
Retrieving latest field note…
Synchronizing published research…
Explore every articleMEDIUM ↗
// Field log

EXPERIENCE
IN MOTION.

Security Specialist — MXDR365 | Security Analyst

Patriot Consulting Technology Group · Managed detection and response across Microsoft security platforms.

Security Engineer / SOC

DIMIYA Tech · SOC technologies, cloud security, detections and automated response workflows.

Cyber Security Analyst

NOVAIZE · Research and testing for an AI-driven threat detection engine.

Cyber Security Engineer Intern

MillenniumIT ESP · Microsoft Sentinel, FortiSIEM, DCRs, KQL and enterprise SOC implementations.

BSc (Hons) Computer Security

University of Plymouth · First Class Honours · Final aggregate 70%.

// Open channel

LET'S BUILD
THE UNBREAKABLE.

Have an opportunity, difficult security problem or research idea? Send the first signal.

lakshan.sam28@gmail.com