|
Vulnerability research & security disclosures acknowledged under the Google Android VRP. |
Acknowledged by NVIDIA Product Security Incident Response Team for responsible vulnerability reporting. |
Responsible vulnerability disclosures acknowledged by the Indian Computer Emergency Response Team. |
|
Authoring custom YARA rules, Sigma detection patterns, and optimizing SIEM alert correlation matrices. |
Auditing cloud IAM policies, container security posture, and serverless threat vectors. |
Developing custom Python scripts for threat intelligence scraping, log parsing, and recon pipelines. |
🛡️ Security Operations Center (SOC) & Incident Response Playbooks (Click to Expand)
- Threat Detection & Triage: Analyzing SIEM alerts (Splunk ES & Sentinel), correlating log sources, and identifying threat indicators.
- Incident Response: Containment, triage, and root-cause post-mortem analysis adhering to NIST guidelines.
- Threat Hunting: Proactive hunting using IOCs, YARA rules, and anomaly detection across network traffic.
⚔️ Penetration Testing (VAPT) & Vulnerability Assessment (Click to Expand)
- Reconnaissance & OSINT: Attack surface mapping using Amass, Nmap, Sublist3r, and Google Dorking.
- Vulnerability Assessment: Testing for OWASP Top 10 vulnerabilities (SQLi, XSS, SSRF, IDOR, Logic Flaws).
- Remediation & Reporting: Writing clear, actionable vulnerability disclosure reports with remediation guidance.