Skip to content
View hiteshus816's full-sized avatar
๐Ÿซ 
Open To Work
๐Ÿซ 
Open To Work

Block or report hiteshus816

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
hiteshus816/README.md

Hi, I'm Hitesh Chowdary Bandaru ๐Ÿ‘‹

Security Operations & Application Security Engineer

๐ŸŽ“ M.S. Cybersecurity & Information Assurance
University of Central Missouri (Expected May 2026)

๐Ÿ›ก๏ธ SOC Analyst | Application Security | Cloud Security | DevSecOps


๐Ÿ‘จโ€๐Ÿ’ป About Me

I'm a cybersecurity professional with experience across Security Operations Center (SOC), Application Security, Cloud Security, and DevSecOps.

My background includes monitoring enterprise environments, investigating security incidents, performing vulnerability assessments, integrating security into CI/CD pipelines, and securing cloud workloads across AWS and Azure.

I enjoy building security labs, automating security workflows, documenting technical research, and continuously improving offensive and defensive security skills.


๐ŸŽฏ Career Interests

  • Security Operations Center (SOC)
  • Threat Detection & Incident Response
  • Application Security
  • Cloud Security
  • DevSecOps
  • Detection Engineering
  • Threat Hunting

๐Ÿ”ญ Currently Learning

  • Advanced Threat Hunting
  • Detection Engineering
  • Microsoft Sentinel
  • Splunk ES
  • Malware Analysis
  • Kubernetes Security
  • Advanced Cloud Security
  • HTB CPTS Labs

๐Ÿ›  Technical Skills

Security Operations

  • Splunk SIEM
  • Splunk SOAR
  • CrowdStrike Falcon
  • Snort IDS/IPS
  • Proofpoint
  • ServiceNow

Threat Intelligence & Vulnerability Management

  • Qualys
  • Recorded Future
  • MITRE ATT&CK
  • Threat Hunting
  • Incident Response
  • Vulnerability Assessment

Application Security

  • Checkmarx (SAST)
  • Burp Suite Professional (DAST)
  • Snyk (SCA)
  • Secure Code Review
  • Threat Modeling
  • OWASP Top 10
  • OWASP ASVS

Cloud Security

AWS

  • GuardDuty
  • CloudTrail
  • Security Hub
  • IAM

Microsoft Azure

  • Defender for Cloud
  • Azure AD
  • Key Vault

DevSecOps

  • Jenkins
  • Azure DevOps
  • Git
  • Docker
  • Secure CI/CD Pipelines

Programming & Scripting

  • Python
  • PowerShell
  • Bash
  • Java

Security Frameworks

  • NIST 800-53
  • PCI-DSS
  • SOX
  • MITRE ATT&CK
  • STRIDE

๐Ÿš€ Featured Projects

๐Ÿ”น Active Directory Attack Lab

Enterprise Active Directory lab covering:

  • AD Enumeration
  • Privilege Escalation
  • Kerberoasting
  • Lateral Movement
  • BloodHound Analysis
  • Evil-WinRM
  • PowerView

Tools

  • BloodHound
  • PowerView
  • Impacket
  • Evil-WinRM
  • CrackMapExec

๐Ÿ”น SOC Detection Lab

Built a SOC lab for monitoring and investigating security events.

Topics include:

  • Log Analysis
  • Threat Detection
  • Alert Investigation
  • Windows Event Logs
  • Incident Triage

Tools

  • Splunk
  • Sysmon
  • Windows Event Viewer
  • Sigma Rules

๐Ÿ”น Vulnerability Management Lab

Performed enterprise-style vulnerability assessments.

Topics:

  • Asset Discovery
  • Vulnerability Prioritization
  • Risk Assessment
  • Remediation Validation

Tools

  • Qualys
  • Nessus

๐Ÿ”น Application Security Lab

Hands-on AppSec testing covering:

  • SAST
  • DAST
  • Dependency Scanning
  • OWASP Top 10

Tools

  • Burp Suite Professional
  • Checkmarx
  • Snyk

๐Ÿ”น Cloud Security Lab

AWS & Azure security monitoring and hardening.

Topics:

  • IAM Best Practices
  • CloudTrail Analysis
  • GuardDuty Findings
  • Azure Defender
  • Key Vault Security

๐Ÿ“œ Certifications

  • โœ… CompTIA Security+
  • ๐ŸŽฏ Preparing for:
    • GIAC GCIH
    • AWS Security Specialty
    • Microsoft AZ-500

๐Ÿ“ˆ GitHub Goals

  • Security Research
  • Detection Rules
  • Sigma Rules
  • SOC Playbooks
  • Blue Team Labs
  • Cloud Security Projects
  • Application Security Labs
  • Python Security Automation

๐Ÿค Connect With Me

๐Ÿ“ง Email
hiteshmark04@gmail.com

๐Ÿ’ผ LinkedIn
https://www.linkedin.com/in/hitesh-bandaru

๐Ÿ’ป GitHub
https://github.com/hiteshus816


"Security isn't about finding vulnerabilitiesโ€”it's about understanding how systems fail, defending them effectively, and continuously improving resilience."

Pinned Loading

  1. ARP-Cache-Poisoning-MITM-Attack-Lab ARP-Cache-Poisoning-MITM-Attack-Lab Public

    Demonstrated ARP cache poisoning attacks using ARP requests, ARP replies, and gratuitous ARP messages. Performed Man-in-the-Middle (MITM) attacks against Telnet and Netcat communications using Scapโ€ฆ

    Python

  2. DNS-Cache-Poisoning-Local-DNS-Spoofing-Attack-Lab DNS-Cache-Poisoning-Local-DNS-Spoofing-Attack-Lab Public

    Demonstrated DNS spoofing and DNS cache poisoning attacks in a controlled lab environment using Scapy and Python. Manipulated DNS responses, injected forged authority and additional records, poisonโ€ฆ

    Python

  3. Firewall-Exploration-Lab-Stateless-Stateful-Firewalls-Load-Balancing Firewall-Exploration-Lab-Stateless-Stateful-Firewalls-Load-Balancing Public

    Implemented and tested Linux iptables firewall rules including stateless filtering, stateful packet inspection, connection tracking, rate limiting, and load balancing using NAT and packet distributโ€ฆ

  4. Metasploit-SMB-Exploitation-Lab Metasploit-SMB-Exploitation-Lab Public

    Full attack simulation using Metasploit: SMB exploitation, post-exploitation, and reverse shell payload delivery

  5. powershell-post-exploitation-lab powershell-post-exploitation-lab Public

    Hands-on PowerShell post-exploitation lab demonstrating file discovery, credential hunting, ping sweep, and port scanning in a simulated environment.

  6. Hydra-Password-Cracking-Wordlist-Analysis-Lab Hydra-Password-Cracking-Wordlist-Analysis-Lab Public

    Hands-on lab demonstrating password list analysis and brute-force concepts using Hydra. Includes wordlist filtering, password policy checks, and service enumeration with real-world attack simulation.