Skip to content
View Niraj-Bathani's full-sized avatar

Block or report Niraj-Bathani

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Niraj-Bathani/README.md

Hi, I'm Niraj Bathani

Windows & SOC Operations Focused | Splunk, Wazuh, QRadar | Detection Engineering | Incident Response | Active Directory & Windows Infrastructure

I build hands-on cybersecurity and enterprise infrastructure labs focused on:

  • SIEM monitoring and detection engineering
  • Windows enterprise administration
  • Incident investigation and troubleshooting
  • Active Directory and Group Policy operations
  • Log analysis and operational validation
  • Blue-team workflows using real telemetry

My projects are designed to simulate real-world enterprise operations using structured documentation, investigation workflows, and validated lab-generated evidence.


About Me

I am a cybersecurity and Windows infrastructure learner focused on developing practical blue-team and operational administration skills through hands-on lab environments.

My work combines:

  • SIEM monitoring and alert analysis
  • Detection engineering
  • Windows Server administration
  • Active Directory operations
  • Group Policy troubleshooting
  • Incident response documentation
  • DNS and DHCP troubleshooting
  • PowerShell automation
  • Enterprise operational workflows

I focus on learning by building realistic environments, generating real telemetry, validating detections, and documenting investigations using enterprise-style operational standards.


Featured Projects

Enterprise System Administration Operations Lab

Production-style Windows Server administration and incident response lab environment.

Highlights

  • Built a Windows Server 2022 enterprise lab environment
  • Configured:
    • Active Directory
    • DNS
    • DHCP
    • Group Policy
    • SMB file services
    • NTFS permissions
  • Implemented department-based access control using security groups
  • Performed:
    • Client-side troubleshooting
    • Group Policy validation
    • DNS troubleshooting
    • File share investigations
    • Standard-user testing
  • Developed enterprise-style incident response documentation including:
    • Issue reports
    • Diagnosis
    • Root cause analysis
    • Remediation
    • Prevention guidance
    • Lessons learned
  • Created PowerShell operational workflows and validation procedures
  • Captured evidence using:
    • Event Viewer
    • PowerShell transcripts
    • Administrative consoles
    • Client validation screenshots

Technologies

  • Windows Server 2022
  • Active Directory
  • Group Policy
  • DNS / DHCP
  • PowerShell
  • SMB / NTFS Permissions
  • Event Viewer
  • RSAT
  • Windows 10/11
  • Ubuntu Server

🔗 https://github.com/Niraj-Bathani/enterprise-system-admin-ops


Splunk SIEM SOC Lab

Enterprise-style SIEM monitoring and investigation environment using Splunk Enterprise.

Highlights

  • Built a multi-host SIEM environment using Splunk Enterprise
  • Ingested Windows and Linux telemetry
  • Developed detections for:
    • PowerShell abuse
    • Authentication failures
    • Persistence techniques
    • LOLBins (certutil)
  • Investigated simulated attack activity using SPL queries and event evidence
  • Practiced SOC investigation workflows and event correlation

Technologies

  • Splunk Enterprise
  • Windows Event Logs
  • Linux logs
  • Sysmon
  • PowerShell
  • VMware

🔗 https://github.com/Niraj-Bathani/splunk-siem-soc-lab


Wazuh SOC Detection Lab

Detection engineering and alert validation environment using Wazuh SIEM.

Highlights

  • Implemented Wazuh with Windows and Linux agents
  • Generated alerts using rule-based detections
  • Simulated attack scenarios and validated alert generation
  • Practiced SOC alert investigation and triage
  • Documented detection workflows and investigation evidence

Technologies

  • Wazuh
  • Linux
  • Windows
  • Sysmon
  • Event Logs

🔗 https://github.com/Niraj-Bathani/wazuh-soc-detection-lab


QRadar Offense Analysis

SOC-style alert investigation and offense analysis using IBM QRadar.

Highlights

  • Investigated QRadar offenses and authentication alerts
  • Analyzed brute-force login activity
  • Practiced:
    • Alert triage
    • Event correlation
    • Investigation workflows
    • Offense analysis
  • Documented findings and remediation workflows

Technologies

  • IBM QRadar
  • Windows logs
  • Linux logs
  • Authentication events

🔗 https://github.com/Niraj-Bathani/qradar-offense-analysis


Core Competencies

SOC & Detection Engineering

  • SIEM Monitoring
  • Detection Engineering
  • Alert Triage
  • Event Correlation
  • Incident Investigation
  • MITRE ATT&CK Mapping
  • SPL Query Development

Windows Infrastructure

  • Active Directory
  • Group Policy
  • DNS
  • DHCP
  • Windows Server Administration
  • NTFS & SMB Permissions
  • RSAT Administration

Security Operations

  • Windows Event Log Analysis
  • PowerShell Investigation
  • Authentication Analysis
  • Persistence Detection
  • Reconnaissance Detection
  • Operational Troubleshooting

Automation & Administration

  • PowerShell
  • Administrative Validation
  • System Health Checks
  • Operational Documentation
  • Troubleshooting Runbooks

Tools & Technologies

SIEM & Monitoring

  • Splunk Enterprise
  • Wazuh
  • IBM QRadar

Windows Infrastructure

  • Windows Server 2022
  • Active Directory
  • Group Policy
  • DNS / DHCP
  • Event Viewer
  • RSAT

Security & Detection

  • Sysmon
  • Suricata (basic)
  • Windows Security Logs
  • Linux Authentication Logs

Operating Systems

  • Windows 10/11
  • Ubuntu Server
  • Kali Linux

Virtualization

  • VMware
  • Host-only Networking
  • NAT Networking

Current Focus

I am currently focused on improving:

  • Detection engineering workflows
  • Splunk SPL query development
  • Windows event analysis
  • SOC investigation methodology
  • Active Directory troubleshooting
  • Incident response documentation
  • Sysmon-based detections
  • Operational validation workflows

What I'm Working On Next

  • Expanding detection coverage with new attack scenarios
  • Building SOC investigation playbooks
  • Creating structured detection engineering labs
  • Improving alert correlation workflows
  • Developing PowerShell investigation tooling
  • Exploring advanced Windows logging and Sysmon detections

Goal

My goal is to become a:

  • SOC Analyst
  • SIEM Engineer
  • Detection Engineer
  • Blue-Team Operations Analyst

by building practical, investigation-driven projects that reflect real-world enterprise security operations and Windows infrastructure administration.


Contact

Popular repositories Loading

  1. Niraj-Bathani Niraj-Bathani Public

    1

  2. qradar-offense-analysis qradar-offense-analysis Public

    SOC offense investigation and SIEM triage with IBM QRadar, including brute-force detection and analyst-style incident documentation

    Python

  3. wazuh-soc-detection-lab wazuh-soc-detection-lab Public

    SOC Detection Engineering & Incident Investigation with Wazuh across Linux and Windows endpoints

    Shell

  4. splunk-siem-soc-lab splunk-siem-soc-lab Public

    Splunk-based home SOC lab for Windows and Linux log analysis, detection engineering, and security investigation workflows.

    PowerShell

  5. enterprise-system-admin-ops enterprise-system-admin-ops Public

    Production-style Windows Server 2022 administration lab focused on Active Directory, Group Policy, DNS/DHCP, PowerShell automation, file server permissions, and enterprise incident response documen…

    PowerShell

  6. enterprise-linux-admin-ops enterprise-linux-admin-ops Public

    Enterprise Linux Administration Operations Lab for RHEL 9.6 featuring hands-on labs, troubleshooting scenarios, monitoring workflows, Bash automation scripts, networking diagnostics, storage manage…

    Shell