Skip to content

Defense // Blue Team

Arunathish
R V

Cybersecurity Analyst — Blue Team with Red Team Knowledge

SOC-style investigations, threat hunting, malware analysis, and log correlation across Splunk, Wazuh, ELK, and Suricata — every finding mapped back to MITRE ATT&CK before it becomes a missed detection.

Offense // Red Team Knowledge

Adversary
Awareness

API security assessment · responsible disclosure · HTB pentesting path

Working knowledge of offensive tradecraft — API assessment, enumeration, and a chained attack path built for a real responsible disclosure — used to sharpen the defense on the other side of the wire.

SectionAbout

About

Blue team by trade.
Red team by understanding.

A cybersecurity analyst working the blue team side of the wire — SOC-style investigations, threat hunting, malware analysis, digital forensics, and SIEM log correlation across Splunk, Wazuh, and the ELK Stack, framed against MITRE ATT&CK so every detection has a reason behind it.

That defense is backed by red team knowledge — an authorized FastAPI security assessment, a chained responsible disclosure, and the HTB Academy penetration tester path — because understanding how an attacker actually moves makes the detection logic that follows sharper.

Backed by enterprise networking experience from a college infrastructure internship — VLANs, ACLs, routing, and Windows-based environments seen from the inside.

Build

Projects

Independent and academic work — built, documented, and defended end to end.

2024 – 2025 · Capstone Architecture Final Year Project
Detecting Cyber Attacks in Web Applications Using Honeypot with Distributed Log Management

Designed and deployed a centralized attack-monitoring platform that collects, correlates, and visualizes attack telemetry from multiple security tools in one unified pipeline — Attacker → Honeypot → IDS → SIEM → Kibana Dashboard.

  • Deployed Cowrie Honeypot, Suricata IDS, and Wazuh SIEM feeding directly into Logstash, Elasticsearch, and Kibana.
  • Simulated SSH brute-force attacks, web reconnaissance activity, and malicious login attempts to generate realistic telemetry.
  • Tuned Suricata detection rules, reducing recurring false positives during simulated attack scenarios.
  • Correlated critical Windows Event IDs (4624, 4625, 4672, 4688, 7045) to reconstruct attack timelines and adversary behavior.
  • Built Kibana dashboards visualizing authentication anomalies, brute-force bursts, and privilege escalation events.
Cowrie HoneypotSuricata IDSWazuh SIEM ELK StackElasticsearchLogstash KibanaUbuntuPython
Self-Directed Lab · 2025 Identity
Active Directory Lab & Identity Control

Built a lab-based Domain Controller environment to understand enterprise identity, authentication protocols, and access enforcement from the inside.

  • Built a lab Domain Controller and integrated Windows endpoints for authentication testing.
  • Configured domain users, security groups, and basic Group Policy Objects for access enforcement.
  • Analyzed authentication logs to detect abnormal Kerberos/NTLM login patterns and privilege usage.
Active DirectoryGroup Policy KerberosNTLMWindows Server
Home Lab Research · 2025 Network Visibility
DNS Filtering & Traffic Visibility

Implemented DNS-level security using Pi-hole and NextDNS to evaluate how DNS filtering, query logging, and policy enforcement improve — and limit — network visibility.

  • Deployed Pi-hole as a local DNS sinkhole to block ad networks, trackers, and malicious domains.
  • Configured NextDNS with security policies to compare cloud-based vs local DNS filtering.
  • Monitored DNS query logs to analyze endpoint activity and outbound domain requests.
  • Investigated the impact of DNS over HTTPS/TLS on endpoint monitoring visibility.
  • Tested network segmentation scenarios to observe visibility changes across isolated networks.
Pi-holeNextDNSDNS Analysis DoH / DoTNetwork MonitoringTraffic Analysis

Offense Knowledge

Security Research & Responsible Disclosure

Authorized assessments and responsible disclosures — mapped to MITRE ATT&CK.

Independent Assessment · 2026 Red Team Knowledge
FastAPI Security Assessment

Performed a security assessment of a FastAPI web application to analyze REST API vulnerabilities, authentication controls, and secure endpoint design.

  • Identified and mapped API endpoints through manual exploration and request inspection.
  • Tested authentication & authorization mechanisms for access control weaknesses.
  • Validated input handling to check for improper validation and potential injection risks.
  • Analyzed HTTP headers, status codes, and JSON responses for information disclosure.
FastAPIREST API SecurityAuth Testing HTTP ProtocolTechnical Reporting
Feb 2026 · Verified Disclosure Red Team Knowledge
Institutional Web Infrastructure Disclosure

Identified and responsibly disclosed multiple web infrastructure misconfigurations, chaining low-severity findings into a realistic attack path.

  • Identified exposed Git repositories, directory listings, unauthenticated JSON endpoints, and indexed documents.
  • Demonstrated a realistic attack path chaining reconnaissance, information disclosure, and credential exposure.
  • Mapped identified techniques to MITRE ATT&CK and delivered structured remediation recommendations.
  • Received formal institutional acknowledgment for the disclosure.
ReconnaissanceInfo Disclosure Attack Path MappingMITRE ATT&CK

Field

Experience

Enterprise networking foundations & practical SOC investigation simulation.

Mar 2025 – May 2025

Network Support Engineer Intern

Amrita Vishwa Vidyapeetham — Nagercoil

  • Configured VLAN segmentation and ACL policies across enterprise network infrastructure to improve network isolation and security.
  • Diagnosed DNS, IP addressing, routing, and connectivity issues in production environments using protocol-level troubleshooting.
  • Maintained network configurations and access control documentation, supporting operational stability and audit readiness.
  • Gained hands-on experience with enterprise network architecture, authentication workflows, and Windows-based environments.

2025 – 2026

SOC Operations Simulation

Hack The Box Academy · LetsDefend · TCM Security · TryHackMe

  • Performed security monitoring and alert triage across endpoint, authentication, and network telemetry following SOC investigation playbooks.
  • Investigated phishing attacks by analyzing email headers, URLs, attachments, and domain indicators via VirusTotal & URLScan.
  • Conducted static and dynamic malware analysis to identify persistence mechanisms, command-and-control activity, and IOCs.
  • Performed Windows forensic investigations using Event Viewer, Sysmon, Process Monitor, Registry artifacts, and Services.
  • Applied MITRE ATT&CK techniques to classify adversary behavior and documented findings in structured case reports.

Academic

Education

2021 – 2025 · Undergraduate Degree

B.E. — Computer Science & Engineering

Amrita College of Engineering, Nagercoil, Tamil Nadu

Comprehensive foundation in computer science principles, computer networking, operating system internals, database management, and software security.

Computer Networks & Security Operating Systems Distributed Systems Database Management Web Application Development

Stack

Skills & Tools

Blue-team core, backed by malware analysis, forensics, and red-team-adjacent tooling.

SIEM & Detection

Splunk · ELK · Wazuh · Suricata

SplunkWazuhElasticsearch LogstashKibanaSuricata IDS

Threat Detection & IR

Alert triage · threat hunting · MITRE ATT&CK

Alert TriageThreat HuntingLog Correlation IOC InvestigationTimeline ReconstructionMITRE ATT&CK Mapping Detection TuningSigmaYARA

Windows & Endpoint

Event logs · Sysmon · registry & process analysis

Windows Event LogsSysmonProcess Monitor Process ExplorerRegistry AnalysisScheduled Tasks Autoruns

Malware Analysis & RE

Static & dynamic analysis · PE inspection

PE StudioDetect It EasyFLOSS HxDCutterx64dbgx32dbg

Digital Forensics

Artifact & event log analysis

FTK ImagerEvent Log ExplorerEric Zimmerman Tools TCPView

Networking & Identity

Protocols · authentication · DNS visibility

TCP/IPDNSDoH / DoTHTTP/HTTPS SMBWiresharkActive Directory Kerberos & NTLMGroup Policy

Threat Intelligence & Scripting

Enrichment · automation

VirusTotalURLScanPython PowerShellBashSQLOSQuery

Red Team Knowledge

API testing · recon · assessment tooling

NmapNiktoSQLMap NessusCyberChefVelociraptor

Proof

Credentials & Verified Profiles

Certifications, training paths, and public profiles you can verify directly.

SOC 101 — Security Operations Center FundamentalsTCM Security
SOC 201 — Intermediate Security Operations & Incident ResponseTCM Security
Windows ForensicsTCM Security
Practical Malware Analysis & TriageTCM Security
Penetration Tester Job PathHack The Box Academy
SOC Analyst Learning PathLetsDefend
Blue Team Labs — Top 15% rankingTryHackMe

Always shipping

Investigation write-ups and research are being published on GitHub — with more incoming.

SOC case reports, malware analysis notes, detection logic, and an OSINT attack-path playbook are in progress. Star the repos to follow along as new investigations land.

Visit GitHub →

Contact

Contact

Open to SOC, threat hunting, and detection
engineering roles. Let's talk.