Alert Triage & Investigation
End-to-end validation, attack timelines, evidence capture, escalation and shift handover.

I engineer calm inside digital chaos—turning threat signals into resilient defenses.
↘I build detection and response systems that make complex threats legible, actionable and hard to repeat.
From Microsoft Sentinel and Defender XDR to identity investigations, SIEM engineering and incident response, my work connects technical depth with evidence-led decisions.
WHOIS / LSAM
Security is technical. Trust is human. I bring both to every investigation, engineering decision and client conversation.
Public identity — Lakshan SameerBuilt from live MSSP and MXDR operations—not a keyword list.
End-to-end validation, attack timelines, evidence capture, escalation and shift handover.
Password spray, impossible travel, suspicious sign-ins, Entra ID and Microsoft 365 telemetry.
KQL/SPL rules mapped to MITRE ATT&CK, tuning, phishing and brute-force playbooks.
Multi-tenant monitoring, SLA-led incident lifecycle, client summaries and remediation guidance.
Every marker is derived from a named feed. No random routes, inflated counters or simulated incidents.
AWAITING SOURCE RECORDS
DShield aggregates reports from distributed intrusion-detection and honeypot sensors. The points show source countries for its top attacking /24 networks; they do not claim to represent every cyberattack worldwide. Locations are country centroids because the public feed supplies a country code—not precise device coordinates.
READ DSHIELD METHODOLOGY ↗Checking the provider’s recommended C2 feed…
Threat research and defensive updates prioritized for Sentinel, Azure, Defender and Entra.
Select a capability to reveal its operational relationships.
Every capability maps to real experience, tools and delivered projects.
Protecting modern environments through engineered visibility, precise investigation and response.
KQL analytics, correlation logic and tuned detection across Microsoft Sentinel and Defender XDR.
↗Alert triage, incident investigation, attack timelines and evidence-based escalation.
↗Authentication anomaly analysis, account compromise validation and cloud attack-path investigation.
↗Threat analysis, adversary behavior, vulnerability assessment and practical defensive guidance.
↗A searchable record of certifications and earned badges across security operations, cloud, networking and threat analysis.
A living archive of builds, research and security experiments.
AWS ◆ MICROSOFT SENTINEL ◆ SPLUNK ◆ KQL ◆ WAZUH ◆ GUARDDUTY ◆ MITRE ATT&CK ◆ PYTHON ◆ SOAR ◆ THREAT INTELLIGENCE ◆ AWS ◆ MICROSOFT SENTINEL ◆ SPLUNK ◆ KQL ◆ WAZUH ◆ GUARDDUTY ◆ MITRE ATT&CK ◆ PYTHON ◆ SOAR ◆ THREAT INTELLIGENCE ◆
Practical security research—from exploit reproduction and SOC engineering to threat-intelligence pipelines.
Patriot Consulting Technology Group · Managed detection and response across Microsoft security platforms.
DIMIYA Tech · SOC technologies, cloud security, detections and automated response workflows.
NOVAIZE · Research and testing for an AI-driven threat detection engine.
MillenniumIT ESP · Microsoft Sentinel, FortiSIEM, DCRs, KQL and enterprise SOC implementations.
University of Plymouth · First Class Honours · Final aggregate 70%.
Have an opportunity, difficult security problem or research idea? Send the first signal.
lakshan.sam28@gmail.com ↗