Secure sessionhandshake
00
Establishing encrypted channel
Rajul Gupta — SOC Analyst
Open to work — London, UK

RajulGupta

SOC Analyst◆Threat Hunter◆Penetration Tester

MSc Cybersecurity & Digital Forensics at UWTSD London, with 1.5+ years across security consulting, IAM and software engineering. I build the SIEM, run the attack against it, then write the rule that catches it next time.

Rajul Gupta avatar
Wazuh
Kali
ThreatIQ

Rajul Gupta

SOC Analyst · London

MSc Cyber & Forensics
19 certifications
wazuh — alerts.liveLIVE
0Triaged
0Missed
0Indexed
About 01

Built from both sides
of the firewall

Profile

I started as a frontend developer at WebMobril — shipping React Native apps, wiring up Firebase, handling DNS and live deployments. Knowing how software is actually built is what makes breaking it interesting.

Two consulting internships followed: SailPoint IAM access reviews, MFA and RBAC enforcement and Zero Trust design at Diaas, then VAPT assessments and hardening on client web infrastructure at Seth Champaran House.

Now I run a full home SOC lab — Wazuh and Splunk on one side, Kali on the other. Custom XML detection rules mapped to MITRE ATT&CK, and ThreatIQ, an AI threat-intel platform that turns raw IOCs into SOC-ready reports in seconds.

Detection rate
100%
658 of 658 caught
Credentials
0
Active certifications
MITRE ATT&CK — techniques exercised in lab
CoverageLow → high
Local time — London
--:--:--
Available immediately · UK & remote
Focus areas

SOC operations and alert triage · threat hunting and detection engineering · digital forensics and incident response · identity governance · cloud and network security.

Also
State-level karate champion
Discipline transfers
Languages
English C1
Hindi
EF SET certified 70/100
Interactive 02

Run an IOC through it

ThreatIQ is my threat-intelligence platform: drop in an IP, domain, URL or file hash and it returns a SOC-ready verdict. This is a front-end simulation of that pipeline running on sample data — the real build lives on GitHub.

ThreatIQ · IOC Analyzer

Demo mode — sample intel
Known bad IP Suspicious domain Malware hash Clean IP
Waiting for input. Pick a sample above or paste your own indicator, then hit Analyze.
Simulated output. The production pipeline queries VirusTotal, AbuseIPDB, GreyNoise, AlienVault OTX, ThreatFox, MalwareBazaar and URLScan.

Attack chain replay — SSH brute force, lab capture

Recon
Nmap scan
Access
Hydra
Exploit
vsftpd
Escalate
Root shell
Detect
Wazuh

Recon. Nmap SYN scan across the lab subnet from the Kali host. 658 alerts fired in Wazuh in real time — port sweep signatures and connection-rate anomalies, before a single credential was tried.

T1046 · Network Service Discovery
Capability 03

Skills & tooling

Built through real internships, a self-run SOC lab and 19 hands-on certifications — pick a track.

Wazuh SIEM / XDR92
MITRE ATT&CK mapping88
Splunk & SPL dashboards85
Wireshark / packet analysis80

What that looks like

658 alerts triaged in the lab with none missed, custom XML rules written from scratch and mapped to ATT&CK tactics, and a five-panel Splunk SOC dashboard covering alert trends, source IPs, rule IDs and high-severity counts.

Alert triageThreat huntingSigma rulesLog analysisIR workflow
Kali Linux90
Nmap / Hydra87
Metasploit Framework82
SQLMap / Burp Suite78

What that looks like

Hydra SSH brute force against a live target with every failed attempt caught before login, a vsftpd exploit through Metasploit for a full root shell, and SQLMap pulling seven databases out of DVWA — each attack replayed on the detection side afterwards.

VAPTBrute forceSQLiPrivilege escalationOWASP
Check Point Gaia NGFW85
Active Directory / DNS / DHCP80
Google Cloud Platform78
Fortinet network security75

What that looks like

A two-site enterprise network built end to end: Check Point gateway at the perimeter under central SmartConsole management, a rulebase authored from scratch with written justification per rule, IPS and anti-malware enabled, plus AD, DNS and DHCP relay across both sites.

IPSIdentity awarenessSite-to-siteDockerHardening
SailPoint IAM83
OWASP / data loss prevention80
Zero Trust architecture78
NIST / ISO frameworks76

What that looks like

Access reviews and role assignments run in SailPoint to enforce least privilege, user provisioning and group policy on Windows Server, MFA and RBAC rolled out across the environment, and OSINT-driven threat modelling feeding into risk assessments.

MFARBACAccess reviewsOSINTGovernance
Selected work 04

Labs, tools & builds

Drag or scroll sideways
01

Home SOC Lab

Wazuh and Splunk self-hosted in VirtualBox with Kali attacking Metasploitable2. Nmap scans fired 658 real-time alerts. Hydra SSH brute force was caught on every failed attempt before login. Metasploit exploited vsftpd for a root shell, and SQLMap pulled seven databases out of DVWA.

WazuhSplunkKaliMetasploit
GitHub
02

Detection engineering

Wazuh rules written from scratch in XML and mapped to MITRE ATT&CK tactics, then piped live into Splunk with 580+ events indexed. Built a five-panel SOC dashboard covering alert trends, source IPs, rule IDs and high-severity counts.

XML rulesATT&CKSPLDashboards
03

Enterprise firewall

Check Point Gaia gateway deployed as the network perimeter under central SmartConsole management. Full rulebase authored with documented justification per rule, IPS and anti-malware enabled, Identity Awareness for role-based access, and site-to-site connectivity with AD, DNS and DHCP relay.

Check PointIPSActive Directory
04

ThreatIQ platform

Analyses IPs, domains, URLs and hashes, then generates SOC-style reports in seconds: IOC enrichment, severity scoring, MITRE mapping, CVE and CVSS correlation, kill chain reconstruction and auto-generated Sigma rules — cross-validated across seven intelligence sources.

Threat intelSigmaCVE / CVSSAI
GitHub
05

Production websites

Humpty Dumpty Preschool and Seth Champaran House, shipped end to end — design, Lottie animation, technical SEO, DNS configuration and live hosting. Both still running in production and still bringing in enquiries.

UI / UXSEODNSDeployment
06

CTF & competition

Preparing for the WorldSkills UK Cyber Security entry stage — Linux CLI, PCAP analysis, OSINT and theory rounds. Timed practice alongside coursework, because triage speed is a skill you have to train under pressure.

PCAPOSINTLinux CLI
Career 05

The path here

2026 — PresentMSc

MSc Cybersecurity & Digital ForensicsThreat intelligence · forensics · incident response

  • Running live SOC lab simulations and enterprise firewall coursework on Check Point Gaia
  • Blue team exercises, threat intelligence research and digital forensics investigations
  • Evidence acquisition, chain of custody documentation and incident response reporting
UWTSD LondonLondon, UK
Jul — Sep 2025Internship

Associate Security ConsultantWeb infrastructure security & hardening

  • Identified vulnerabilities across client-facing web infrastructure and contributed to VAPT documentation
  • Applied practical hardening and secure deployment practices using OWASP guidance
  • Led the company's official website end to end — design, DNS configuration and live deployment
Seth Champaran HouseRemote
Apr — Jun 2025Internship

Associate Security ConsultantIdentity & access management

  • Ran SailPoint access reviews and role assignments, enforcing least privilege across the environment
  • Handled provisioning, group policy and access controls on Windows Server and Active Directory
  • Enforced MFA and RBAC, contributed to Zero Trust design and ran OSINT threat modelling
DiaasRemote
Feb — Aug 2024Full-time

Frontend DeveloperReact Native · Firebase · deployment

  • Built React Native mobile and web applications with Firebase and Firestore backends
  • Managed DNS, domain setup and coordinated live production deployments
  • Learned how applications actually break — from the side that builds them
WebMobril Gaming StudiozIndore, India
Jul — Dec 2023Full-time

Data AssociateData quality & reporting

  • Filtered and cleaned lead data at volume, keeping records accurate and usable
  • Built Excel reporting and maintained email documentation standards
  • Unglamorous work that built the methodical habit now used for alert triage
Relay Human CloudAhmedabad, India
2019 — 2023B.Tech

Computer ScienceCloud Technology & Information Security

  • Graduated with 7.70 CGPA across a four-year cloud and security specialisation
  • Coursework in cloud storage, network security and software engineering
  • Hands-on work with Google Cloud, GitHub and foundational security tooling
Medi-Caps UniversityIndore, India
Credentials 06

19 certifications

Across security operations, offensive testing, networking, cloud and compliance.

Fortinet Certified Associate in Cybersecurity
FortinetMar 2026 — Mar 2028ID 7629095278RG
Executive Certification in Cyber Security & Ethical Hacking
iHUB DivyaSampark · IIT RoorkeeNov 2025ID TIHLVPL251166
Introduction to Critical Infrastructure Protection
OPSWAT AcademyMar 2026 — Feb 2027ID 8hFz7IJKRA
ACT Security e-Learning
Nactso · CT Policing & SIAMar 2026
Docker Foundations Professional Certificate
Docker, IncMar 2026
Learning Docker
LinkedInMar 2026
Cisco Network Security: Core Security Concepts
LinkedInFeb 2026
Ethical Hacking & Penetration Testing Module
LearnbayDec 2025ID 94315ko
Advance Cybersecurity Techniques
LearnbayJan 2026ID 10032ten
Cybersecurity & Information Security Essentials
LearnbayJan 2026ID 1005aht7h
Junior Cybersecurity Analyst Career Path
CiscoAug 2025
The Basics of Google Cloud Compute
GoogleApr 2025
Networking Fundamentals on Google Cloud
GoogleApr 2025
Protect Sensitive Data with Data Loss Prevention
GoogleApr 2025
Google Cloud Cybersecurity Certificate
GoogleFeb 2025
Cybersecurity Fundamentals
IBMJan 2025
Network Security
The Open UniversityJan 2025
Ethical Hacker
CiscoJan 2025
EF SET English Certificate 70/100 (C1)
EF SETMar 2025
Contact 07

Actively looking for SOC Analyst, Security Analyst and Cloud Security roles across the UK. Email is the fastest route.

RolesSOC · Security · Cloud
LocationLondon + remote
NoticeImmediate
Security awarenessACT certified