Jitbahan Samanta
SOC SME, SIEM admin, Splunk admin
- Role
- Associate Consultant at Tata Consultancy Services
- Location
- Pune, MH, IN
- LinkedIn followers
- 500 followers
About Jitbahan Samanta
A self-motivated and committed professional, capable of dealing with the customer…
Experience
Associate Consultant
Feb 2020 — Present · Pune, IN
Performing triage, in-depth and root cause analysis of Security incidents, correlating events. Analyzing events to identify potential threat vectors and attack pattern. Carrying out detailed analysis of suspicious/critical events on daily basis to proactively hunt for potential security threats in environment. Threat hunting in the environment. understanding of MITRE framework Malware analysis Performing manual analysis of logs from different devices and carrying out a trend analysis with historical data and events to predict and identify any potential threats. Performed Splunk Upgrade and ES app, involved in pre and post upgrade activities. Experience of working on all set up and configuration files. Experience of installations and configuration of various Splunk components like indexer, search heads, HF’s, UF’s, deployment server, license master, indexer clustering. Health checks and troubleshooting. Worked on Splunk configuration files. Worked on custom port creation for syslog-ng at universal forwarder and configuration of source, destination, and log folder configuration files for onboarding logs via syslog. Worked on log ingestion from cloud sources O365 management activity logs, O365 message trace logs, O365 defender logs, Azure AD sign in logs, Azure audit logs, AWS CloudTrail, AWS CloudWatch Network devices logs, VPN, proxy logs, CISCO AMP, WAF, Cisco Umbrella Proxy logs through Amazon S3 bucket, Crowdstrike, Tenable, CISCO ASA Firewall, Palo Alto firewall & IPS logs, MacAfee logs through DB Connect, Tenable IO vulnerability, asset and Plugin data, threat intelligence data. Worked on use case development and use case creation. Use Case Mapping with MITRE ATT & CK framework Worked on Splunk alerts, reports, dashboards, saved searches as per client requirements. Troubleshooting and resolving issues related to log stoppage. Worked on Various add-ons and input configurations of those add-ons.
Education
SRM University
Master of Technology (M.Tech.), Information Security and Cyber Forensics
2013 — 2015
Swami Vivekananda Institute Of Science And Technology
Bachelor of Technology (B.Tech.), Computer Science
2008 — 2012
Skills
- Nikto
- Security Incident Response
- Security Incident & Event Management
- Nexpose
- Nmap
- Web Application Security Assessment
- Firewalls
- Kali Linux
- Rational Appscan
- Penetration Testing
- Burp Suite
- Vulnerability Management
- C
- Threat Analysis
- Vulnerability Scanning
- Openvas
- Threat Intelligence
- Vulnerability Assessment
- Siem
- Qualys
- Nessus
- Information Security
- Metasploit
- Qradar
- Log Analysis
- Threat & Vulnerability Management
Find verified contacts for anyone on LinkedIn
Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.
Free plan included · No credit card required
This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.