Skip to content
View AmalUBasnayake's full-sized avatar
πŸ’­
πŸ›‘οΈ Building real-world security labs | AZ-500 candidate
πŸ’­
πŸ›‘οΈ Building real-world security labs | AZ-500 candidate

Block or report AmalUBasnayake

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
AmalUBasnayake/README.md

Hi πŸ‘‹ I'm Amal Udayanga Basnayake

Cybersecurity Engineer | Azure Security | SIEM | Threat Detection | Blue Team


πŸ‘¨β€πŸ’» About Me

πŸ” Cybersecurity and cloud-focused IT professional with 5+ years of experience in enterprise IT operations, specializing in SIEM engineering, cloud security, and threat detection across large-scale environments.

  • 🏒 IT & Systems Specialist managing Microsoft 365 security for 4,000+ users
  • πŸ›‘οΈ Hands-on with Microsoft Sentinel, Splunk, Azure Defender, and SOAR automation
  • ☁️ Focused on Azure Cloud Security Architecture & Identity Protection (Entra ID / MFA / PIM)
  • πŸ”¬ Built 28+ real-world cybersecurity labs covering SOC, SIEM, and cloud security
  • πŸ“œ ISO/IEC 27001:2022 Lead Auditor | CRTOM | CSCSO | Blue Team Analyst
  • πŸ“š Advancing toward AZ-500 Microsoft Azure Security Engineer (Expected Q3 2026)

πŸ† Key Achievements

Achievement Impact
Enforced MFA & Conditional Access across 4,000+ accounts Significantly reduced unauthorized access risk
Deployed endpoint hardening baselines across all managed devices Improved compliance rate organization-wide
Built SOAR-automated incident response workflows Reduced mean time to respond (MTTR)
Reduced system downtime at previous role 35% improvement through proactive monitoring
Improved help desk resolution efficiency 40% faster through structured escalation

πŸ›‘οΈ Core Security Skills


πŸš€ Featured Cybersecurity Projects

πŸ”΅ SOC / SIEM Engineering

Project Description
Microsoft Sentinel SIEM Threat Detection Lab Built end-to-end threat detection pipeline with custom KQL analytics rules
Sentinel SOAR Automated IP Blocking Automated incident response malicious IP blocking via Logic Apps
Honeypot Live Attack Map Deployed Azure honeypot with real-time global attack visualization
SOC Dashboard Monitoring Lab Built comprehensive SOC monitoring dashboard with alert triage workflows
Brute Force Attack Detection Detected and responded to brute force attacks using Sentinel analytics

☁️ Azure Cloud Security

Project Description
Azure Firewall Hub-Spoke Architecture Enterprise-grade secure network segmentation in Azure
Azure WAF + Application Gateway Security Web traffic inspection with OWASP rule sets
Azure DDoS Protection Lab Cloud-native volumetric attack mitigation
Azure Key Vault Hardening Secrets management and cryptographic key protection
Conditional Access + MFA Security Lab Identity-based Zero Trust access enforcement
IAM + Privileged Identity Management (PIM) Just-in-time privileged access controls

πŸ” Threat Detection & Analysis

Project Description
Splunk Real-Time Security Dashboard Real-time threat visibility with custom Splunk dashboards
Windows Persistence Detection using Sysmon Endpoint threat hunting for persistence mechanisms
Registry-Based Threat Detection Detecting malicious registry modifications
Active Directory Monitoring AD event log analysis for attack pattern detection
Network Traffic Analysis Deep packet inspection and anomaly detection

πŸ“œ Certifications

  • πŸŽ“ Pearson BTEC Level 5 HND in Cybersecurity Achievers International Campus (2024 – 2026) | Distinction – Digital Forensics | Distinction – ISMS | Merit – Cybersecurity

  • πŸ”„ AZ-500 Microsoft Azure Security Engineer (In Progress Q3 2026)

  • βœ… ISO/IEC 27001:2022 Lead Auditor

  • βœ… CRTOM Certified Red Team Operations Management

  • βœ… CSCSO Certified SME Cyber Security Officer

  • βœ… Blue Team Junior Analyst Pathway

  • βœ… ISC2 Candidate

  • βœ… CCNA Cisco Networking Academy

  • βœ… Cyber Threat Management Cisco Networking Academy

  • βœ… MS-102 Microsoft 365 Administration Learning Path

  • βœ… Wireshark & Network Analysis


πŸ“Š GitHub Stats


πŸ“ˆ GitHub Activity Graph


🌐 Security Portfolio

πŸ”— amalcyberlab.vercel.app Real-world cybersecurity labs, writeups, and security projects.


⭐ 28+ real-world cybersecurity labs | SOC Operations | SIEM Engineering | Azure Cloud Security | Threat Detection

Pinned Loading

  1. Windows-Endpoint-Security-Monitoring-Sysmon Windows-Endpoint-Security-Monitoring-Sysmon Public

    Implementing advanced system telemetry and endpoint monitoring using Microsoft Sysmon with a hardened configuration to detect suspicious process executions and system modifications.

  2. Live-Network-Security-SIEM-Lab Live-Network-Security-SIEM-Lab Public

    A real-time Network Security Monitoring (NSM) lab that captures live traffic using TShark and visualizes security insights on a Splunk SIEM Dashboard. Features automated data ingestion and proactiv…

    1

  3. Splunk-Realtime-Network-SOC-Dashboard Splunk-Realtime-Network-SOC-Dashboard Public

    A professional real-time Security Operations Center (SOC) dashboard built with Splunk and TShark to monitor 2.6M+ network events with live intensity alerts.

  4. Azure-Sentinel-Honeypot-Live-Attack-Map Azure-Sentinel-Honeypot-Live-Attack-Map Public

    A cloud-native SIEM project using Microsoft Sentinel to visualize real-time RDP brute-force attacks from around the globe. This project features a custom PowerShell script and IP-geolocation integr…

  5. Azure-Sentinel-SOAR-Auto-IP-Block Azure-Sentinel-SOAR-Auto-IP-Block Public

    An automated Incident Response (SOAR) solution using Microsoft Sentinel and Azure Logic Apps to dynamically extract malicious IPs and block them in Azure Network Security Groups (NSG) in real-time.

  6. Azure-DDoS-Protection-HandsOn-Lab Azure-DDoS-Protection-HandsOn-Lab Public

    A hands-on lab demonstrating the implementation of Azure DDoS Network Protection, simulating a TCP Flood attack using PowerShell, and monitoring real-time mitigation via Azure Monitor Metrics