MSc Cybersecurity & Digital Forensics at UWTSD London, with 1.5+ years across security consulting, IAM and software engineering. I build the SIEM, run the attack against it, then write the rule that catches it next time.
I started as a frontend developer at WebMobril — shipping React Native apps, wiring up Firebase, handling DNS and live deployments. Knowing how software is actually built is what makes breaking it interesting.
Two consulting internships followed: SailPoint IAM access reviews, MFA and RBAC enforcement and Zero Trust design at Diaas, then VAPT assessments and hardening on client web infrastructure at Seth Champaran House.
Now I run a full home SOC lab — Wazuh and Splunk on one side, Kali on the other. Custom XML detection rules mapped to MITRE ATT&CK, and ThreatIQ, an AI threat-intel platform that turns raw IOCs into SOC-ready reports in seconds.
Detection rate
100%
658 of 658 caught
Credentials
0
Active certifications
MITRE ATT&CK — techniques exercised in lab
CoverageLow → high
Local time — London
--:--:--
Available immediately · UK & remote
Focus areas
SOC operations and alert triage · threat hunting and detection engineering · digital forensics and incident response · identity governance · cloud and network security.
Also
State-level karate champion
Discipline transfers
Languages
English C1 Hindi
EF SET certified 70/100
Interactive 02
Run an IOC through it
ThreatIQ is my threat-intelligence platform: drop in an IP, domain, URL or file hash and it returns a SOC-ready verdict. This is a front-end simulation of that pipeline running on sample data — the real build lives on GitHub.
ThreatIQ · IOC Analyzer
Demo mode — sample intel
Known bad IPSuspicious domainMalware hashClean IP
Waiting for input. Pick a sample above or paste your own indicator, then hit Analyze.
Simulated output. The production pipeline queries VirusTotal, AbuseIPDB, GreyNoise, AlienVault OTX, ThreatFox, MalwareBazaar and URLScan.
Recon. Nmap SYN scan across the lab subnet from the Kali host. 658 alerts fired in Wazuh in real time — port sweep signatures and connection-rate anomalies, before a single credential was tried.
T1046 · Network Service Discovery
Capability 03
Skills & tooling
Built through real internships, a self-run SOC lab and 19 hands-on certifications — pick a track.
Wazuh SIEM / XDR92
MITRE ATT&CK mapping88
Splunk & SPL dashboards85
Wireshark / packet analysis80
What that looks like
658 alerts triaged in the lab with none missed, custom XML rules written from scratch and mapped to ATT&CK tactics, and a five-panel Splunk SOC dashboard covering alert trends, source IPs, rule IDs and high-severity counts.
Hydra SSH brute force against a live target with every failed attempt caught before login, a vsftpd exploit through Metasploit for a full root shell, and SQLMap pulling seven databases out of DVWA — each attack replayed on the detection side afterwards.
VAPTBrute forceSQLiPrivilege escalationOWASP
Check Point Gaia NGFW85
Active Directory / DNS / DHCP80
Google Cloud Platform78
Fortinet network security75
What that looks like
A two-site enterprise network built end to end: Check Point gateway at the perimeter under central SmartConsole management, a rulebase authored from scratch with written justification per rule, IPS and anti-malware enabled, plus AD, DNS and DHCP relay across both sites.
IPSIdentity awarenessSite-to-siteDockerHardening
SailPoint IAM83
OWASP / data loss prevention80
Zero Trust architecture78
NIST / ISO frameworks76
What that looks like
Access reviews and role assignments run in SailPoint to enforce least privilege, user provisioning and group policy on Windows Server, MFA and RBAC rolled out across the environment, and OSINT-driven threat modelling feeding into risk assessments.
MFARBACAccess reviewsOSINTGovernance
Selected work 04
Labs, tools & builds
Drag or scroll sideways
01
Home SOC Lab
Wazuh and Splunk self-hosted in VirtualBox with Kali attacking Metasploitable2. Nmap scans fired 658 real-time alerts. Hydra SSH brute force was caught on every failed attempt before login. Metasploit exploited vsftpd for a root shell, and SQLMap pulled seven databases out of DVWA.
Wazuh rules written from scratch in XML and mapped to MITRE ATT&CK tactics, then piped live into Splunk with 580+ events indexed. Built a five-panel SOC dashboard covering alert trends, source IPs, rule IDs and high-severity counts.
XML rulesATT&CKSPLDashboards
03
Enterprise firewall
Check Point Gaia gateway deployed as the network perimeter under central SmartConsole management. Full rulebase authored with documented justification per rule, IPS and anti-malware enabled, Identity Awareness for role-based access, and site-to-site connectivity with AD, DNS and DHCP relay.
Check PointIPSActive Directory
04
ThreatIQ platform
Analyses IPs, domains, URLs and hashes, then generates SOC-style reports in seconds: IOC enrichment, severity scoring, MITRE mapping, CVE and CVSS correlation, kill chain reconstruction and auto-generated Sigma rules — cross-validated across seven intelligence sources.
Humpty Dumpty Preschool and Seth Champaran House, shipped end to end — design, Lottie animation, technical SEO, DNS configuration and live hosting. Both still running in production and still bringing in enquiries.
UI / UXSEODNSDeployment
06
CTF & competition
Preparing for the WorldSkills UK Cyber Security entry stage — Linux CLI, PCAP analysis, OSINT and theory rounds. Timed practice alongside coursework, because triage speed is a skill you have to train under pressure.