Most SOC dashboards are built to look busy, not to catch anything. I care more about the ten log lines that actually mattered than the thousand that didn't.
Associate SOC Engineer at Investis Digital, Vadodara, India. I work in the space between an alert firing and someone actually understanding what happened — triage, correlation, and AI-augmented detection that turns raw noise into a decision someone can act on.
Outside work, I build things that prove the concepts I claim to know instead of just listing them — 19 repos spanning SIEM/SOAR platform breadth, CrowdStrike Falcon, the full Microsoft security stack, AI/LLM security, and GRC — every one of them run and verified before it shipped.
| 10K+ | 18 min | 30% | 5× |
|---|---|---|---|
| Alerts triaged | Mean time to detect (down from 4 hrs) | False positives cut via ML tuning | Faster detection rule development |
| 9.47 | 40+ | Top 1% | 8+ |
|---|---|---|---|
| CGPA — Gold Medal, Cyber Forensics | Verified certifications | TryHackMe global ranking | HackTheBox machines pwned |
Every number above is drawn directly from real SOC work at Investis Digital and independently verifiable certifications — nothing here is aspirational.
| 19 | 160+ | 6 | 0 |
|---|---|---|---|
| Repos, each with a real README stating what's verified vs. researched | Automated checks passing across the repos with formal test suites | Real SDKs/APIs integrated — FalconPy, Microsoft Graph, GitHub API, pySigma, Bicep CLI, CACAO | Fabricated results — every honest gap is named in its own repo, not hidden |
🏛 Flagship platforms
| Project | What it answers |
|---|---|
| MSE-Platform | Can a full Microsoft Zero Trust enterprise architecture — identity to AI ops — be built as real, Bicep-CLI-validated Infrastructure-as-Code instead of a single-tool lab? (all 8 phases complete) |
| SIEM-Tool-Matrix | Can a real ingest-to-alert pipeline plus honest research on all 24 major SIEM platforms live in one place? |
| SOAR-Playbook-Matrix | A real OASIS CACAO execution engine, an AI playbook generator, and honest research on 18 SOAR platforms. |
| Falcon-Platform-Matrix | All 15 CrowdStrike Falcon modules — RTR, Spotlight, Identity, Cloud, Fusion SOAR — with real, verified FalconPy SDK code. |
| grc-compliance-platform | Framework crosswalk, live GitHub control checks, and real policy-drift detection — found real drift on the first run. |
🎯 Detection engineering & validation
| Project | What it answers |
|---|---|
| atlas-purple-team | Do AI-SOC-Copilot's defenses actually hold up against real MITRE ATLAS techniques? Ran it — green on prompt injection, red on jailbreak/exfiltration, against real vendored code. |
| purple-team-validator | Do my Sigma rules actually catch the real attacks they claim to? 2/3 failed first try — the bug was in my own test harness, not the rules. |
| Detection-as-Code | Can one Sigma rule generate real, correct native queries for Splunk, Elastic, Sentinel, CrowdStrike, and QRadar at once? |
| Sentinel-Detection-Response-Pack | Six ATT&CK-mapped detections, two SOAR playbooks, and a cloud posture check, shipped as deployable code. |
🤖 AI security
| Project | What it answers |
|---|---|
| AI-SOC-Copilot | Can an LLM triage alerts safely when the alert data itself is attacker-controlled? |
| CyberShield-AI | Can phishing/malware triage be scored transparently — rule-by-rule — instead of hidden behind a black-box model? |
| VishGuard | Can social-engineering attacks be caught by their behavioral pattern, regardless of whether the voice is real or deepfaked? |
🛠 SOC foundations
| Project | What it answers |
|---|---|
| SOC-Lab-Open-Source-Setup | Can a full detection-and-response pipeline be built entirely on open-source tooling? |
| Kibana-SIEM-Dashboard-Demo | What does a correlation rule look like from raw log to dashboard alert? |
| SOC-Alert-Notifier | Can alert routing be automated without losing the analyst's judgment in the loop? |
| SOC-Incident-Case-Study | What does a real incident look like end-to-end — detection, response, and the lesson learned? |
⚔️ Offensive & recon
| Project | What it answers |
|---|---|
| ReconVeritas | How much of manual recon can be safely automated into one modular workflow? |
| RedTeam-WAF-Detection-Bypass-Lab | If I were attacking my own detections, where would they break? |
| Wireshark-HTTP-Credential-Capture | What does an attacker actually see on unencrypted traffic — hands-on, not theoretical? |
A shareable snapshot, built for LinkedIn, not a filing cabinet.