SIEM & Threat Detection
LogRhythm, Splunk, ELK Stack, Wazuh, and EDR consoles.
- • Incident triage
- • Rule correlation
- • MITRE ATT&CK mapping
I’m Moataz Mostafa Ali Ibrahim, a Cybersecurity Analyst and Computer Science student with hands-on experience in Python scripting, Linux log analysis, SIEM workflows, and practical IT support.
Current focus
Threat detection
Simulating phishing, brute-force, and log-analysis scenarios using MITRE ATT&CK.
Automation angle
Python-based tools for parsing auth logs, scanning TCP ports, and speeding up triage.
Infrastructure support
Assisting users with hardware, OS diagnostics, network basics, and Microsoft Office workflows.
About Me
I’m dedicated to building reliable defenses through structured detection, incident awareness, and hands-on technical support. My experience blends practical IT work with cybersecurity simulations, helping me connect system reliability and security operations in a meaningful way.
I’m especially interested in threat hunting, incident response, and applying Python automation to speed up investigations and improve visibility across Linux and Windows environments.
Technical skill stack
A practical mix of SIEM operations, networking fundamentals, Python automation, and hands-on IT support.
LogRhythm, Splunk, ELK Stack, Wazuh, and EDR consoles.
TCP/IP, DNS, routing, Wi-Fi architecture, Wireshark, and Nmap.
Python, Bash, PowerShell, Agentic AI tools, and Linux automation.
Hardware troubleshooting, Windows diagnostics, basic network setup, and user training.
Professional experience
Cybersecurity Virtual Experience Program
Mastercard via Forage • 06/2026
Functioned as a security awareness analyst, identifying phishing patterns, decoding logs, and recommending training improvements for vulnerable business units.
General IT & Technical Support Specialist
Self-Employed • 2015 – Present
Delivered PC troubleshooting, Windows diagnostics, software deployment, identity baseline support, and basic training aligned to ICDL and Microsoft Office practices.
Hands-on projects
Selected work demonstrating practical detection, scripting growth, and incident-response thinking.
Built a Python script that extracts failed sudo attempts and flags suspicious brute-force traffic from system logs.
Impact: improved simulated triage speed and pattern detection clarity.
Created a command-line utility using Python’s socket module to quickly identify open ports on a target host.
Use case: rapid recon and basic service discovery in homelab scenarios.
Practiced L1 SOC workflows in ELK Stack and Wazuh, including log filtering, rule matching, packet review, and structured incident reporting.
Outcome: stronger understanding of alert handling, timelines, and evidence preparation.
Explored command-line AI agents and PowerShell scripts to automate baseline maintenance and accelerate logging reviews.
Focus: practical automation supporting security hygiene and reporting.
Education & credentials
Bachelor of Science in Computer Science
University of the People (UoPeople) • 2026 – Present
Focus: advanced computing logistics, secure network topologies, and database integrity.
Relevant training
Computer Network Fundamentals — ITI, CompTIA Network+ — LinkedIn Learning, Learning Python for Cybersecurity — LinkedIn Learning, Linux Administration & Identity Management — LinkedIn Learning.
Certifications
Certified in Cybersecurity (CC)
ISC2 • Active Member
CompTIA Cybersecurity Analyst (CySA+)
In Progress / Self-Study
Languages
Arabic — Native proficiency
English — Professional Working Proficiency