Active
--:--:-- UTCSyed Dayaan Shah
Watchfloor · Online|Node OP-SDS-04|Sec+ · CWNA · CCNA
Auth · O5
Syed Dayaan Shah

Syed Dayaan Shah

Houston · Sector 01

IT Engineer — Security Operations Focus

Session uptime00:00:00:00
Watch roleBlue team · Tier-1
StatusSOC watch · active
Global intercept · live
Inbound000
Blocked000
Breach000
Defense000

Realtime SIEM feed

logs flowing
    $ tail -f /var/log/siem/*.evt _

    Ops telemetry

    72% capacity

    Alerts triaged (24h)

    412

    MTTD (rolling)

    3m 7s

    Hosts monitored

    214

    Risky sign-ins (7d)

    9

    Active detections

    62

    Uptime SLO

    99.97%

    ATT&CK coverage95%
    • Initial Access
    • Execution
    • Persistence
    • Priv Esc
    • Defense Evasion
    • Cred Access
    • Discovery
    • Lateral
    • C2
    • Impact
    covered partial
    Live feed|> tls handshake ok · endpoint 04A2 online
    [01]Authentication · Verified

    About the operator

    Syed Dayaan Shah — portrait

    ID · OP-SDS-04

    • ·Goes by Eddie
    • ·21 · Karachi → Dubai → Houston at 12
    • ·Lone Star College · AAS Cybersecurity
    • ·Xbox loyalist · Watch Dogs 2 & Cricket 26

    Hey, I'm Dayaan Shah. I'm 21, and most people who actually know me call me Eddie. I was born in Pakistan, spent my early years bouncing between Karachi and Dubai, and my family moved to Houston when I was 12. Middle school, high school, and college all happened here in Texas. I picked up my Associate in Cybersecurity at Lone Star College, and honestly most of my coursework was networking — VLANs, routing and switching, wireless, firewalls — which is where I really got hooked on this stuff.

    Outside of work I'm a pretty heavy gamer. Right now I'm deep into Watch Dogs 2, which is kind of on-brand because that whole hacker vibe is what pulled me into security in the first place. I'm also a big cricket guy, so when I'm not gaming red-team scenarios I'm playing Cricket 26 on my Xbox. And yeah, I'm an Xbox loyalist. PC and PlayStation just aren't for me. During the day I'm an IT Engineer with a security operations focus at Integris, the biggest MSP in the country, after getting promoted out of the support engineer seat, and I'm working my way toward a full SOC analyst role.

    [02]Service History

    Deployment history

    Roles across MSP, wireless network administration, and security-analyst work.

    1. Current Deployment

      Jan 2026 — Present

      Remote

      IT Engineer — Security Operations Focus

      Integris

      Promoted from IT Support Engineer

      • Triage roughly 25–40 SIEM, endpoint, and identity alerts per shift across Microsoft Sentinel and Defender XDR, closing about 85% at my level with a documented determination.
      • Investigate Entra ID account-takeover attempts — risky sign-ins, MFA fatigue, token replay — and contain confirmed compromise the same shift, cutting alert-to-containment from hours to under 45 minutes.
      • Analyze 50–70 phishing and BEC reports a month with Defender for Office 365, Mimecast, message trace, VirusTotal, and urlscan.io; purge campaigns tenant-wide and tune transport rules.
      • Maintain EDR coverage across ~1,500 endpoints (Defender for Endpoint, SentinelOne) and run PowerShell + Microsoft Graph sweeps for bulk sign-in and mailbox-rule audits.
      • Map findings to MITRE ATT&CK and document incidents against NIST 800-61 so scope, root cause, and containment are defensible in client review.
    2. Chapter · 05

      Aug 2025 — Jan 2026

      Remote

      IT Support Engineer

      Integris

      • Delivered security-focused Tier 1–2 support across SMB and enterprise Microsoft 365 hybrid tenants — identity, endpoint, access control, and network incidents.
      • Administered Microsoft 365 and Entra ID: MFA enforcement, Conditional Access, provisioning, mailbox security, and authentication troubleshooting.
      • Escalated suspicious sign-ins and account-compromise events to the security team with clean evidence timelines, which led to the move into the security operations seat.
    3. Chapter · 04

      Jan 2025 — Aug 2025

      Houston, TX

      SOC Analyst I — Security Operations

      NetRobin

      Promoted from Wireless Network Administrator

      • Worked a live queue of 25–40 endpoint and email alerts per shift, escalating confirmed incidents with full timeline, IOCs, and containment recommendation.
      • Analyzed 30–40 phishing messages a month using VirusTotal, urlscan.io, and AbuseIPDB; blocked sender infrastructure and pulled matching mail across tenants.
      • Hunted beaconing and DNS anomalies in Wireshark and firewall logs; added detections for repeat offenders.
      • Ran Nessus and OpenVAS cycles with CVSS-based prioritization, driving critical and high findings down across client sites and verifying with re-scans.
    4. Chapter · 03

      Aug 2024 — Jan 2025

      Houston, TX

      Wireless Network Administrator

      NetRobin

      Promoted from Junior IT Support Specialist

      • Conducted wireless site surveys; optimized AP placement, VLAN/SSID design, and interference minimization.
      • Deployed and hardened WAPs across client campuses, tightening 802.1X/WPA2-Enterprise auth and hunting rogue APs.
      • Implemented proactive monitoring and configuration audits to keep networks compliant and performant.
    5. Chapter · 02

      Jan 2024 — Aug 2024

      Houston, TX

      Junior IT Support Specialist

      NetRobin

      • Provided Tier 1–2 support for 15+ SMB clients, resolving 20–30 tickets a day via RMM tooling.
      • Managed Active Directory, DNS, DHCP, and Microsoft 365 (user creation, MFA setup) to maintain 99% uptime.
      • Collaborated with network engineers on secure infrastructure across multi-tenant environments.
    6. Chapter · 01

      Mar 2023 — Jan 2024

      Houston, TX

      IT Security Analyst Intern

      Ai IT Studio

      • Supported 10–15 security investigations a week across firewall, endpoint, and email telemetry.
      • Assisted with firewall administration, detection tuning, and real-time threat monitoring.
      • Ran vulnerability assessments with CVE triage and tracked patch remediation to completion on Windows and Linux endpoints.
    [03]Case Files

    Six operations. Four full guided labs.

    Every card opens a full write-up. LAB cards ship with an interactive, step-by-step simulation — brief, your move, live result, how I stopped it, how you prevent it.

    [04]Skill Telemetry

    Toolbox & capability matrix

    Signal readings — self-assessed proficiency against real production workloads.

    SOC / Detection

    • SIEM monitoring (Splunk, Sentinel)88%
    • Threat detection & hunting84%
    • Incident response support86%
    • Endpoint security (Defender XDR)85%

    Identity & Cloud

    • Entra ID / Azure AD90%
    • MFA & Conditional Access88%
    • Active Directory87%
    • Microsoft 365 Security89%

    Networking

    • LAN/WAN, VLAN, routing & switching92%
    • Firewalls & VPN troubleshooting86%
    • Wireless (CWNA level)93%
    • Wireshark / SNMP / NetFlow84%

    Vuln & Scripting

    • Nessus / OpenVAS83%
    • Python scripting81%
    • PowerShell / Bash85%
    • IPv4/IPv6 subnetting90%
    [05]Credentials

    Certifications & education

    • CompTIA Security+

      CompTIA · Earned Jun 2026

      SOC-track certification — threats, architecture, operations, IR.

      Active
    • CWNA — Certified Wireless Network Administrator

      CWNP · Jan 2023 — Jan 2026

      Vendor-neutral 802.11 wireless expertise.

      Active
    • CCNA: Switching, Routing & Wireless

      Cisco · Feb 2025

      Enterprise LAN switching, inter-VLAN routing, and wireless fundamentals.

      Active
    • CCNA: Wireless Networks

      Cisco · May 2025

      Wireless LAN design, RF fundamentals, and secure Wi-Fi deployment.

      Active
    • TryHackMe SOC Level 1

      TryHackMe · Earned Jul 2026

      Hands-on SOC path — SIEM, phishing analysis, threat intel, DFIR.

      Active
    • IC3 Digital Literacy

      Certiport · May 2022

      Active

    2024 — 2026

    Associate's Degree — Cybersecurity

    Lone Star College System · Houston, TX

    • Coursework: network security, cybersecurity law, database security, OS hardening.
    • Lab tools: Kali Linux, Cisco Packet Tracer, Wireshark, cloud security platforms.

    Aug 2020 — Jun 2024

    High School Diploma — Cybersecurity Career Pathway

    Klein Oak High School · Houston, TX

    • Hands-on training in network security, digital forensics, ethical hacking.
    • Built secure network environments using Packet Tracer and VirtualBox.
    [06]Uplink Ready

    Establish a secure channel

    Recruiters, hiring managers, and security teams — the fastest path is direct email. Response window: within 24 hours.