Detection & SIEM
Advanced log analytics, event correlation, detection tuning, and automated threat pre-processing pipelines.
01 SOC · Incident response · Active defense
I’m Shalva, a Security Operations Center Analyst (L2) based in Tbilisi. I turn security telemetry into decisive action—tuning detection, investigating threats, and strengthening enterprise environments.
A little context
I bridge deep technical analysis and security strategy—translating noisy telemetry into clear decisions.
At ITCraft, I work across advanced SIEM tuning, event correlation, automated threat pre-processing, enterprise incident response, and multi-vendor network perimeters. My offensive-security mindset helps me investigate how an attack works, not only where it appeared.
My foundation was built in frontline IT support and team leadership at International Black Sea University. That experience still shapes how I operate: stay calm, communicate clearly, find the root cause, and leave the system stronger than before.
How I create value
Advanced log analytics, event correlation, detection tuning, and automated threat pre-processing pipelines.
Escalation handling, root-cause analysis, playbook development, threat hunting, and active defense.
Risk-aware protection across critical endpoints, multi-vendor firewalls, networks, and Linux environments.
TOOLBELT / CAPABILITIES
Professional trajectory
A progression from frontline technical operations to security leadership, investigation, and enterprise defense.
ITCRAFT · TBILISI
Monitoring and investigating enterprise threats, tuning SIEM platforms, improving telemetry correlation, managing escalations, and supporting automated response workflows.
SIEM TUNED THREATS HUNTED RESPONSE ACTIVE
IBSU · ITCRAFT
Led university support operations while coordinating technical resolution, end-user service, systems continuity, and communication across a busy academic environment.
ITCRAFT · IBSU · CAUCASUS UNIVERSITY
Diagnosed hardware, software, network, and user-access issues while maintaining reliable services and building the operational foundation for a move into cybersecurity.
Verified learning
TryHackMe · Issued Dec 2025
THM-EGTUQF4CAITryHackMe · CISA JCDC Triage Fusion and Analysis · Nov 2025—Nov 2035
THM-JVR3U2HPKSTryHackMe · Sep 2025—Sep 2028
THM-2MWEFSMO18TryHackMe · Sep 2025—Sep 2030
THM-YHFGKSGY28TryHackMe · Sep 2025—Sep 2030
THM-TH8U8ODRGSTryHackMe · Sep 2025—Sep 2030
THM-O5YB6D7QMZTryHackMe · Sep 2025—Sep 2028
THM-Y05LJ9JOTYTryHackMe · Sep 2025—Sep 2028
THM-JSEWACT2EYTryHackMe · Sep 2025—Sep 2030
THM-DFCKXEC7ATTryHackMe · Sep 2025—Sep 2030
THM-HEX0VWNFTSUdemy · Issued Sep 2024
UC-52657340-629d-4b45-8a67-31b6d8a791d5SuperMap GIS · Issued Nov 2021
SUPERMAPP GISinfySEC · Issued Jun 2021 · Ethical Hacking
INFYSECGeorgian Project Andromeda · Issued Oct 2020
ANDROMEDANeed sharper security operations?
Open to security operations, incident response, and infrastructure opportunities.