Aspiring SOC Analyst | Defensive Security | Threat Detection
$ cat about.txtCybersecurity student and hands-on learner with a focus on defensive security and SOC operations. I build real labs — honeypots, SIEM pipelines, and detection workflows — to sharpen practical blue-team skills. Currently pursuing B.Tech in CSE at CHARUSAT while actively practicing on LetsDefend, Hack The Box, and CyberDefenders. Seeking an entry-level SOC Analyst / Cybersecurity Analyst role where I can contribute and grow.
| Framework | Application |
|---|---|
| MITRE ATT&CK | Mapping threat behavior to adversary techniques |
| Kill Chain | Understanding attack lifecycle and detection points |
| SOC Workflows | Alert triage → Investigation → Documentation |
| NIST CSF | Risk management concepts |
| OWASP Top 10 | Web application vulnerability awareness |
May 2025 – Jun 2025
- Analyzed real network traffic using Wireshark to detect protocol-level anomalies and suspicious patterns
- Investigated packet captures and log data to identify brute-force attempts and unusual connection behavior
- Documented security findings following SOC-style incident reporting practices
Jul 2023 – Aug 2023
- Developed Android application components using Java/XML in Android Studio
- Implemented UI layouts, activity navigation, and tested across multiple Android devices
Sep 2022 – Oct 2022
- Built a Django-based web application with secure authentication and user management
- Integrated SMTP email functionality and improved application security practices
Deployed a Cowrie SSH honeypot in an isolated lab to capture real-world brute-force attacks. Analyzed credential harvesting attempts, attack timelines, and adversary command execution behavior.
Configured a Wazuh SIEM lab to detect brute-force attempts, malware activity, and file integrity changes across Linux and Windows endpoints. Performed SOC-style alert triage and incident investigation.
Exploring SOAR concepts with automated security response playbooks.
Built tooling to detect phishing indicators and analyze suspicious URLs/domains.
Built a GAN-based synthetic handwriting generator to explore document forgery risks — assessing security implications including signature spoofing and misuse of biometric-like traits.
Actively sharpening blue-team skills through hands-on platforms:
| Platform | Focus |
|---|---|
| 🟢 LetsDefend | Alert triage, SOC workflows, incident analysis |
| 🟠 Hack The Box | Capture the Flag, attack/defense fundamentals |
| 🔵 CyberDefenders | Log analysis, threat investigation scenarios |
| 📝 CTF Challenges | Pattern recognition, creative problem-solving |
| Certification | Issuer | Year |
|---|---|---|
| 🏅 Security Operations Fundamentals | Palo Alto Networks Academy | 2025 |
| 🏅 Into the Trenches: Security Operations Center | EC-Council | 2025 |
| 🏅 Security Operations Center Fundamentals | Cisco | 2025 |
| 🏅 Introduction to Cybersecurity | 2024 | |
| 🏅 Introduction to SIEM | Splunk | 2024 |
| 🏅 Fundamentals of Red Hat Enterprise Linux 9 | Red Hat | — |
🎓 Bachelor of Technology — Computer Science & Engineering
Charotar University of Science and Technology (CHARUSAT) · 2024 – Present
🎓 Diploma — Information Technology
Government Polytechnic Rajkot · 2021 – 2024 · CGPA: 8.6
📝 Building a Production-Ready SIEM Lab: A Comprehensive Wazuh Deployment Guide for SOC Analysts
💼 LinkedIn → linkedin.com/in/vatsalsapovadiya
📧 Email → vatsalsapovadiya22@gmail.com
🌐 Portfolio → vatsalsapovadiya.vercel.app
📝 Blog → medium.com/@vatsalsapovadiya22
🌍 Location → Rajkot, Gujarat, India
🗣️ Languages → English · Hindi · Gujarati
[ Always learning. Always defending. ]
"Security is not a product, but a process." — Bruce Schneier