Defense // Blue Team
Cybersecurity Analyst — Blue Team with Red Team Knowledge
SOC-style investigations, threat hunting, malware analysis, and log correlation across Splunk, Wazuh, ELK, and Suricata — every finding mapped back to MITRE ATT&CK before it becomes a missed detection.
Offense // Red Team Knowledge
API security assessment · responsible disclosure · HTB pentesting path
Working knowledge of offensive tradecraft — API assessment, enumeration, and a chained attack path built for a real responsible disclosure — used to sharpen the defense on the other side of the wire.
SectionAbout
Blue team by trade.
Red team by understanding.
A cybersecurity analyst working the blue team side of the wire — SOC-style investigations, threat hunting, malware analysis, digital forensics, and SIEM log correlation across Splunk, Wazuh, and the ELK Stack, framed against MITRE ATT&CK so every detection has a reason behind it.
That defense is backed by red team knowledge — an authorized FastAPI security assessment, a chained responsible disclosure, and the HTB Academy penetration tester path — because understanding how an attacker actually moves makes the detection logic that follows sharper.
Backed by enterprise networking experience from a college infrastructure internship — VLANs, ACLs, routing, and Windows-based environments seen from the inside.
Build
Independent and academic work — built, documented, and defended end to end.
Designed and deployed a centralized attack-monitoring platform that collects, correlates, and visualizes attack telemetry from multiple security tools in one unified pipeline — Attacker → Honeypot → IDS → SIEM → Kibana Dashboard.
Built a lab-based Domain Controller environment to understand enterprise identity, authentication protocols, and access enforcement from the inside.
Implemented DNS-level security using Pi-hole and NextDNS to evaluate how DNS filtering, query logging, and policy enforcement improve — and limit — network visibility.
Offense Knowledge
Authorized assessments and responsible disclosures — mapped to MITRE ATT&CK.
Performed a security assessment of a FastAPI web application to analyze REST API vulnerabilities, authentication controls, and secure endpoint design.
Identified and responsibly disclosed multiple web infrastructure misconfigurations, chaining low-severity findings into a realistic attack path.
Field
Enterprise networking foundations & practical SOC investigation simulation.
Mar 2025 – May 2025
Amrita Vishwa Vidyapeetham — Nagercoil
2025 – 2026
Hack The Box Academy · LetsDefend · TCM Security · TryHackMe
Academic
2021 – 2025 · Undergraduate Degree
Amrita College of Engineering, Nagercoil, Tamil Nadu
Comprehensive foundation in computer science principles, computer networking, operating system internals, database management, and software security.
Stack
Blue-team core, backed by malware analysis, forensics, and red-team-adjacent tooling.
Splunk · ELK · Wazuh · Suricata
Alert triage · threat hunting · MITRE ATT&CK
Event logs · Sysmon · registry & process analysis
Static & dynamic analysis · PE inspection
Artifact & event log analysis
Protocols · authentication · DNS visibility
Enrichment · automation
API testing · recon · assessment tooling
Proof
Certifications, training paths, and public profiles you can verify directly.
Academy modules, Sherlocks, and practical labs — blue-team focused investigation work.
View profile ↗SOC Analyst learning path — malware, phishing, and Windows investigation case work.
View profile ↗SOC investigations, malware analysis, detection engineering, threat hunting & OSINT write-ups.
View repositories ↗Always shipping
SOC case reports, malware analysis notes, detection logic, and an OSINT attack-path playbook are in progress. Star the repos to follow along as new investigations land.
Contact
Open to SOC, threat hunting, and detection
engineering roles. Let's talk.