Manoj  ·  Dubai, UAE

Security Operations Engineer

Detection,
response, and the hunt
in between.

Nine years across security engineering and threat hunting, with the DFIR and MSSP-SOC years underneath them — the chairs where you learn what telemetry looks like before someone turns it into a rule. Currently engineering for Emirates Group; writing and consulting on the side.

Based inDubai, UAE Open toSenior Engineer & Threat Hunting roles Emailmanoj.komakula@gmail.com LinkedInlinkedin.com/in/manoj-komakula-0101 Writinginsightlayer.in
01

A short note

I started in a junior SOC seat in 2016 and have spent the years since moving deliberately deeper — from L1 triage at GSS Infotech, into L2 MSSP work at NTT Security, into hands-on DFIR at Newfold Digital, then into platform engineering and incident response as Platform Lead II at CyberProof, and now into senior engineering at Emirates Group.

The throughline is detection that survives contact with reality and response that holds together when alerts arrive in batches. I write KQL that doesn't fall over at scale, build Logic App and SOAR pipelines that close the loop instead of paging humans for known-good outcomes, and run forensics engagements where the deliverable is a defensible timeline rather than a tool dump.

Outside hours I run a DFIR and threat-hunting blog at insightlayer.in, maintain a Proxmox-based home lab that I use as a personal detection sandbox, and occasionally take consulting engagements.


02

Where I've worked

Jun 2024 — Present Dubai, UAE

Security Operations Engineer

Emirates Group

An engineering seat inside a complex aviation enterprise, focused on the Microsoft security stack — Sentinel, Defender for Endpoint, Defender for Cloud, Defender for Cloud Apps, and Entra ID — and the workflows that connect them. The work spans detection content, SOAR automation, endpoint policy, identity, and email security; the day-to-day mix shifts with what's burning, but the underlying capability stays the same — turning each platform into something operators can actually run.

On the detection side, that means authoring KQL content across Sentinel and Advanced Hunting against MDE, mapped to MITRE ATT&CK and tuned for signal rather than volume — including the work that surfaced Windows servers running Defender AV in passive or disabled mode and drove remediation across the estate. On automation, it's Logic App playbooks that take known alert classes from page to closure without paging a human, measurably reducing MTTR. Endpoint hardening sits alongside it: ASR rule design, Exploit Protection (EAF / IAF), AV health monitoring, and the Intune / SCCM policy plumbing that actually delivers it.

The other half of the seat is identity and email. Identity work lives at the unfun edge of Entra ID — SSO and MFA flows, SAML mismatches, B2B guest lifecycles, AADSTS error chains, Conditional Access edge cases — the failure modes support tickets get stuck on. Email work is Mimecast policy engineering: closing Auto Allow override behaviour, tightening URL protection and spam scanning, and building detection for QR-code phishing. Underneath all of it: SSL / TLS certificate lifecycle, runbook authoring, and the detection-engineering documentation that lets the next analyst start where I left off.

Jun 2021 — May 2024 India

Platform Lead II

CyberProof (a UST Global company)

A hybrid platform-engineering role with SOC-support work at an MSSP, serving clients across financial services, government, and enterprise verticals. Some weeks were spent building, others responding; the seat covered both ends. Engineering meant standing up Microsoft Sentinel/EDR end-to-end — analytics rules, workbooks, data connectors, Logic App playbooks. KQL detection content was tailored per client, tuned against their telemetry, and mapped to MITRE ATT&CK. SOAR playbooks were built with real enrichment integrations — VirusTotal, AbuseIPDB, customer CMDB — so triage decisions came back enriched rather than raw.

The response half was L3 escalation and IR-lead work across customer environments. That meant deep-dive investigation across endpoint telemetry on Windows, Linux, and macOS; identity, email, and cloud telemetry; static and dynamic malware analysis on recovered samples; and network forensics over full-packet captures, proxy and DNS data, IDS / IPS alerting, and Zeek / Suricata flow analysis to find C2 beaconing, lateral movement, and exfiltration to enhance the EDR capabilites. EDR fluency extended well past MDE — CrowdStrike Falcon, VMware Carbon Black, Cybereason, SentinelOne, Check Point, and Sophos all sat in the platform fleet, each with its own policy and exclusion regime.

Threat hunting was a programme rather than an ad-hoc activity — ATT&CK-driven, hypothesis-led, with reusable hunt packs across Sentinel and MDE Advanced Hunting. On the side: custom log ingestion pipelines (Logic Apps + Azure Functions) for SaaS APIs that lacked native connectors; HLD / LLD documentation aligned to regulatory compliance; Microsoft Purview DLP frameworks; mentoring junior analysts; and customer executive-level briefings on risk posture and security roadmaps.

Sep 2019 — May 2021 India

Security Analyst (SOC + DFIR)

Newfold Digital · Endurance International Group

The battleground. A global web-hosting environment where the adversary surface was both the corporate network and tens of thousands of customer-facing properties — compromised customer sites, web-shell deployments, automated attacks at scale, and live C2 traffic showing up in telemetry every shift. Core SOC analyst by title, deep DFIR by practice: triage across Microsoft Sentinel, Fireeye Helix, and EDR; investigation through to root cause; and full incident response on confirmed compromises — web-server intrusions, credential abuse, phishing-led account takeover, and the kind of mass-scale activity that doesn't fit a vendor playbook.

Host forensics came up daily, on both Linux and Windows, at the artefact level — $MFT, USN Journal, prefetch, registry hives, bash and auth logs, process timelines — used to reconstruct attacker movement and validate the real scope of compromise rather than the apparent one. Memory forensics with Volatility on live or recovered samples. Static and dynamic malware analysis on droppers and binaries to extract IOCs and pivot across the estate. Network-side reconstruction through web-server access and error logs, proxy and DNS telemetry, and IDS / IPS alerts to map entry vectors, lateral movement, and exfiltration paths. Hunting was ATT&CK-aligned across the hosting fleet — anomalous web shells, lateral patterns, persistence mechanisms — and every incident generated detection content that closed the gap the previous one had used. Each engagement closed with an RCA, chain-of-custody documentation, and a write-up engineering could use to harden the platform.

Jan 2018 — Sep 2019 India

Security Analyst

NTT Security (MSSP)

The step out of the L1 chair into real investigation work. L2 SOC analyst across a portfolio of global MSSP clients on a 24/7 shift — owning triage, investigation, and escalation across SIEM, EDR, email security, and network telemetry. Where most of the foundational DFIR muscle was built: leading engagements on malware infections, phishing-led credential theft, and insider-threat scenarios, with end-to-end ownership from initial alert through containment guidance, evidence collection, and post-incident reporting.

Underlying capability covered host-level forensic analysis (prefetch, registry, event logs, browser artefacts, process timelines), phishing analysis with static and dynamic malware triage on email payloads, IOC extraction back into client detection content, and hypothesis-driven threat hunts across client tenants using MITRE ATT&CK to surface dormant compromises and detection gaps. SIEM correlation tuning and new detection content came from incident learnings rather than a roadmap. Client-facing communication mattered as much as the technical work — incident reports, RCAs, and threat advisories written for non-technical stakeholders as cleanly as for engineering audiences.

Nov 2016 — Nov 2017 India

Junior Security Analyst

GSS Infotech

The first chair, and where the security career began. SOC monitoring across SIEM, IDS / IPS, endpoint, and email-security telemetry — alert triage, escalation, and first-pass investigation on malware, phishing, and policy violations. Early hands-on with static and dynamic malware triage on phishing payloads through sandbox and reputation tooling, EDR investigation workflows, and the supporting work that makes the rest possible: DLP policy design, log-source tuning, and correlation rule refinement. The foundation everything else was built on.


03

Tools & terrain

Detection & SIEM

  • Microsoft Sentinel
  • KQL · Sigma · ATT&CK
  • Splunk · ArcSight (legacy)
  • Detection-as-Code patterns

Endpoint & EDR

  • Microsoft Defender for Endpoint
  • Live Response & advanced hunting
  • Intune / SCCM endpoint policy
  • FLARE-VM, Kali, Remnux

Cloud & Identity

  • Microsoft Entra ID · Conditional Access
  • Microsoft Graph (PowerShell / REST)
  • BeyondTrust PAM
  • OAuth2 / OIDC / SAML troubleshooting

DFIR

  • Velociraptor · KAPE · Autopsy
  • Volatility (memory forensics)
  • Zeek · Suricata (network)
  • Timeline construction · chain of custody

Automation

  • Sentinel Logic Apps / playbooks
  • PowerShell (module authoring)
  • Python (scripting & small services)
  • n8n · low-code orchestration

Network & Lab

  • OPNsense · UniFi
  • Network segmentation design
  • Proxmox VE (detection lab)
  • TLS / PKI lifecycle

04

Credentials & study

Certifications

  • eCTHPv2 eLearnSecurity Certified Threat Hunting Professional
  • SC-200 Microsoft Security Operations Analyst Associate
  • SC-401 Microsoft Information Security Administrator

Education

  • M.Tech, Network & Cybersecurity Amity University · 2023
  • B.Tech Kakatiya University · 2015

05

Selected writing

Detection Engineering

Detecting Defender AV passive mode at scale

A walk-through of a real compliance gap on a Windows Server estate — building the KQL, working around case-sensitivity traps in DeviceTvmSecureConfigurationAssessment, and closing the loop with a Logic App.

Read

Threat Hunting

Threat hunting beyond IOCs

A hypothesis-driven framework I've been using since eCTHPv2 — why "go look for evil" doesn't scale, and what to do instead when you have a finite shift and a wide telemetry surface.

Read

Long-form blog

InsightLayer

DFIR notes, threat-hunting walk-throughs, and longer technical pieces I publish on my own site. Where most of my detailed writing lives.

Visit