B.Tech CSE student at MMMUT Gorakhpur (graduating 2027), focused on blue team engineering and DFIR. I build tools — EVTX parsers, network IDS, PCAP analysers, and vulnerability dashboards — and map detections to MITRE ATT&CK. TryHackMe top 3% globally. Co-authored an IEEE paper on Windows authentication forensics.
Currently targeting SOC Analyst and Blue Team Engineer roles. Open to internships at MSSPs and security-focused startups.
Multi-Auth Artifact Correlation Engine · Python · PowerShell
Correlates Windows authentication artifacts across Local, MSA, RDP, and Kerberos auth mechanisms. Parses raw EVTX logs and surfaces anomalous access patterns via a unified anomaly view.
Event IDs covered: 4624 4625 4648 4768 4776
📄 IEEE paper co-authored with Dr. Vimal Kumar, MMMUT
APK Malware Analysis + Fraud Intelligence Platform · Python · React
Built for the PSB Cybersecurity Hackathon 2026 (IIT Hyderabad × Bank of India). Combines a WhatsApp bot for end-user APK scanning with an enterprise SOC dashboard for threat intelligence and fraud pattern detection.
Network Traffic Forensics Tool · Python · dpkt · Wireshark
Deep PCAP inspection — protocol dissection, IOC extraction, and anomaly flagging from captured network traffic.
C++ Network Intrusion Detection System · C++ · libpcap · MITRE ATT&CK
Modular NIDS with a custom PacketCapture → IP → TCP → HTTP parsing pipeline. Pluggable detector architecture via abstract BaseDetector interface. Generates severity-classified, ATT&CK-tagged structured alerts.
Vulnerability Intelligence Dashboard · FastAPI · React
Real-time CVE lookup and vulnerability dashboard. Backend deployed on Render, frontend on Vercel.
| Domain | Tools & Stack |
|---|---|
| Threat Detection | MITRE ATT&CK · Sigma Rules · Custom detection logic · Alert triage |
| Windows Forensics | EVTX parsing · Event IDs · FTK Imager · Autopsy · Registry analysis |
| Network Analysis | PCAP · Wireshark · libpcap · dpkt · Protocol dissection · IOC extraction |
| Incident Response | Log correlation · Timeline analysis · Artifact collection |
| Development | Python · C++ · PowerShell · Bash · FastAPI · React |
| OSINT | Passive recon · Threat intel · Open-source investigation |

