π€ SYSTEM OVERVIEW An offensive-minded and defensive-ready Cybersecurity professional specializing in VAPT, Cloud Infrastructure Defense, and active Bug Hunting. Dual-hatted in uncovering critical infrastructure flaws while mastering SOC Operations, Log Analysis, and Incident Response.
[ Find the gaps ββ> Defend the infrastructure ]
| π΄ OFFENSIVE | π΅ DEFENSIVE |
|---|---|
| VAPT & Web App Testing | SOC Operations & Log Analysis |
| Threat Intelligence Analysis | Email Security & Phishing Triage |
| AI-Driven Vulnerability Discovery | Incident Detection & Response |
π π VIPER-SOC : Vulnerable IP & Payload Eradication Response |
Wazuh SIEM, Python, AbuseIPDB & VirusTotal
- Architected an automated dual-layer SIEM containment framework bridging live threat intelligence with host-level response.
- Engineered custom AbuseIPDB API integrations and Wazuh rules to block malicious network actors via
/etc/hosts.deny. - Configured real-time File Integrity Monitoring (FIM) integrated with VirusTotal to automatically purge malicious file payloads.
- Streamlined automated zero-touch active response playbooks, reducing Mean Time to Respond (MTTR) from minutes to milliseconds.
- Documented full SIEM rule configurations, architecture diagrams, and custom Python integration hooks in an open-source repo.
π π¨ XSS Snort3 Detection |
Python, Snort 3 & Linux
- Designed a hands-on VAPT lab deploying a local Python Flask web application intentionally left vulnerable to Reflected XSS.
- Engineered custom Snort 3 IDS network signatures targeting malicious script tags and raw payload injection patterns.
- Monitored loopback adapter interface streams to analyze network traffic buffers and capture live security flags.
- Successfully generated real-time diagnostic terminal alert logs mapping incoming web-layer exploits instantaneously.
- Documented secure coding input-escaping remediation methods alongside active inline network blocking rule configurations.
- π― Bug Hunting & Coordinated Disclosure: CERT-In (Assigned Case IDs for Kerala Government Web Infrastructure validation), HackerOne, Bugcrowd, and huntr.
- βοΈ Interactive Lab Operations: Network Enumeration, Privilege Escalation, and Advanced Web Labs across TryHackMe, HackTheBox, and PortSwigger Academy.
- ποΈ Certified SOC Analyst (CSA v2) | EC-Council
- π Certified IT Infrastructure & Cyber SOC Analyst (CICSA v3) | Red Team Hacker Academy
- π Bachelor of Computer Applications (BCA) | Indira Gandhi College of Arts And Science
- π Advanced Diploma in Cyber Security and Cloud Computing (Add-On) | STED Council / Skill Development Council Canada
[β‘] SECURING THE FULL DIGITAL LIFECYCLE [β‘]