Bengaluru • Cybersecurity fresher

I build detections that explain themselves.

Labs, SIEM logic and response workflows presented with context: what broke, what I tested, what I learned.

XSIAMWazuhPythonATT&CK
security-lab.yml
Detection coverage86%
Documented labs06
Featured query

cloud_token_anomaly()

Recruiter takeaway

Can investigate, tune and explain.

Selected work

01 / Detection Lab

Suspicious cloud token use

Mapped identity abuse to ATT&CK, wrote detection logic, tested false positives and documented tuning notes.

02 / SOC Flow

Triage workflow

Built a clear investigation path from alert to enrichment to analyst note.

03 / Web Security

Assessment report

Moved beyond screenshots: impact, evidence, fix and retest status.

Proof map

Tools

XSIAM, Wazuh, Linux, Python, Git, Wireshark.

Methods

ATT&CK mapping, alert tuning, enrichment, report writing.

Evidence

Queries, screenshots, architecture diagrams and lessons learned.

Open to security internships.

Fictional Gemmify demo