π Sydney, Australia π¦πΊ
I am a Cybersecurity graduate student specializing in Security Operations (SOC), Detection Engineering, SIEM, and Blue Team Security. I build hands-on security labs that simulate real-world attacks, validate detections, and strengthen defensive capabilities through practical experimentation.
My work combines SIEM engineering, network security, incident response, and machine learning to create reproducible cybersecurity projects that mirror enterprise Security Operations Centers. Every project focuses on detection accuracy, evidence collection, MITRE ATT&CK mapping, and continuous improvement.
- π‘οΈ Building enterprise-style SOC detection engineering labs
- π Developing custom Wazuh detection rules
- βοΈ Learning Microsoft Sentinel
- π¬ Publishing practical cybersecurity research
- πΌ Preparing for SOC Analyst & Detection Engineer roles
Repository
β‘οΈ https://github.com/MrBipinShrestha/soc-home-lab-wazuh
Enterprise-style SOC lab simulating real-world cyber attacks, endpoint monitoring, threat detection, and incident response.
- Multi-agent endpoint monitoring
- Five realistic attack simulations
- SSH brute force detection
- Privilege escalation detection
- Malware persistence analysis
- Data exfiltration monitoring
- Cron backdoor investigation
- MITRE ATT&CK mapping
- Detection engineering validation
- Five professional incident response reports
- β 3/5 attack scenarios automatically detected
- β 2 detection gaps documented
- β Detection improvements recommended
Technology
Wazuh β’ Linux β’ Windows β’ MITRE ATT&CK β’ SIEM
Repository
β‘οΈ https://github.com/MrBipinShrestha/network-anomaly-detection-unsw-nb15
Machine learning pipeline for detecting malicious network traffic using the UNSW-NB15 benchmark dataset.
- Seven-stage ML pipeline
- Feature engineering
- Label encoding
- Z-score normalization
- SMOTE balancing
- Isolation Forest anomaly detection
- Random Forest classification
- Performance evaluation
- Reproducible Jupyter workflow
| Metric | Value |
|---|---|
| Accuracy | 88.3% |
| Attack Recall | 0.98 |
| ROC-AUC | 0.9794 |
Top predictive features
- ct_state_ttl
- sttl
- rate
- sload
- dload
Machine Learning-Driven Network Anomaly Detection: An Empirical Study Using Isolation Forest and Random Forest on the UNSW-NB15 Benchmark
Published in:
Australian Journal of Wireless Technologies, Mobility and Security
https://ausjournal.com/index.php/j/article/view/92
Technology
Python β’ scikit-learn β’ SMOTE β’ Pandas β’ Jupyter
Repository
β‘οΈ https://github.com/MrBipinShrestha/phishing-attack-lab-kit
SOC-focused phishing investigation framework covering email analysis, OSINT, threat intelligence, detection engineering, and prevention.
- Email header analysis
- SPF, DKIM & DMARC validation
- Domain reputation analysis
- Typosquatting detection
- WHOIS investigation
- VirusTotal integration
- MXToolbox analysis
- MITRE ATT&CK mapping
- Detection recommendations
- Five practical investigation labs
Technology
Python β’ VirusTotal β’ WHOIS β’ MXToolbox β’ Wazuh
| Repository | Focus |
|---|---|
| Wireshark HTTP vs HTTPS Analysis | Network Traffic Analysis |
| Malware Detection Lab | Endpoint Security |
| Social Engineering Awareness Lab | Human Threat Analysis |
Machine Learning-Driven Network Anomaly Detection: An Empirical Study Using Isolation Forest and Random Forest on the UNSW-NB15 Benchmark
Australian Journal of Wireless Technologies, Mobility and Security
- π Journal: https://ausjournal.com/index.php/j/article/view/92
- π Google Scholar
- π ORCID: https://orcid.org/0009-0004-2734-1646
- Wazuh
- Security Monitoring
- Detection Engineering
- Log Analysis
- Threat Detection
- MITRE ATT&CK
- TCP/IP
- DNS
- HTTP / HTTPS
- SSH
- Packet Analysis
- Wireshark
- Threat Investigation
- IOC Analysis
- Root Cause Analysis
- Incident Documentation
- Digital Forensics
- Python
- Pandas
- NumPy
- scikit-learn
- Jupyter Notebook
- Linux
- Windows
- VirusTotal
- WHOIS
- MXToolbox
- ClamAV
- Git
- GitHub
- Cisco Introduction to Cybersecurity
- Cisco Cyber Threat Management
- Cisco Endpoint Security
- Fortinet Certified Associate (remove if not completed)
I believe effective security comes from validating detections through practical testingβnot assuming coverage.
Every project follows the same engineering workflow:
Attack
β
Detect
β
Investigate
β
Respond
β
Document
β
Improve Detection
Every published lab includes:
- Attack simulation
- Detection validation
- MITRE ATT&CK mapping
- Evidence collection
- Incident reporting
- Gap analysis
- Detection improvement recommendations
I'm actively seeking opportunities in:
- SOC Analyst
- Detection Engineer
- Blue Team Security
- Security Operations Center (SOC)
- Incident Response
I enjoy collaborating on cybersecurity projects, SIEM engineering, threat detection, and security research.
- πΌ LinkedIn: https://www.linkedin.com/in/shresthabin/
- π» GitHub: https://github.com/MrBipinShrestha
- π ORCID: https://orcid.org/0009-0004-2734-1646
β If you find my work useful, feel free to star my repositories or connect with me on LinkedIn!