Security Operations · Threat Intel · Threat Hunt
DFIR · Malware Analysis · Detection Engineering

Hrushikesh
Badgujar.

Rosh Gadol, not rosh katan. I understand the mission before I execute it.

3YrsSecurity Operations
5YrsCyber Security Field
8Platform Modules
8Certifications
3Published Writeups

M.Tech in Cybersecurity from NFSU, with 3 years across in-house and managed SOC environments. On any given shift, I might be investigating alerts, working with threat intelligence, hunting threats, fine-tuning detections, looking for automation opportunities, or researching something new.

Somewhere between investigating alerts, hunting threats, and doing the same things repeatedly, I started building my own tools. The result is H3AD-SEC, a platform for IOC enrichment, threat hunting, detection engineering, automation, and more.

Rosh Gadol, not Rosh Katan: understand the mission first, then build. The same principle guides my investigations: understand the context before reaching a conclusion.

Every module in H3AD-SEC exists because it solves something I encountered on shift. Built for the work I actually do, not for a demo that looks good.

Education M.Tech Cybersecurity · NFSU
Current Role Associate Specialist · Concentrix
Approach Purpose-built tooling, no demos
May 2024 — Present Current
Associate Specialist Concentrix Daksh Services India Pvt. Ltd.

MDR/XDR SOC operations: alert triage, threat hunting, detection engineering, and building the automation the job actually needed.

Oct 2023 — May 2024
Trainee Cyber, SOC Analyst Gramax Cybersec

24x7 SOC monitoring and incident triage, the entry point into everything that came after.

Security Operations
Alert triage, XDR/EDR monitoring, and SIEM workflows inside a live MDR/XDR SOC environment.
Threat Intelligence
Tracking adversary infrastructure, TTPs, and campaigns, correlating IOCs into structured intelligence that feeds every other discipline.
Threat Hunting
Hypothesis-driven hunting across endpoint, network, and identity telemetry, finding what alerts missed, then codifying it.
Incident Response
Containment, eradication, and recovery for active incidents. Root cause before remediation, always.
Digital Forensics
Registry, memory, and disk artifact analysis, reconstructing what actually happened on a compromised endpoint after the alert fires.
Automations
Triage queries, enrichment pipelines, and workflow tooling that remove analyst toil so teams focus on decisions, not data wrangling.
Detection Engineering
Detection logic built around attacker behavior, not just indicators: Sigma rules, SIEM tuning, and detection-as-code pipelines.
AI Security
Using LLMs for triage, hunt hypothesis generation, and detection engineering, plus the prompt-injection and AI-abuse risks defenders now have to cover.
Security Operations
SOC Monitoring Alert Triage & Escalation Incident Response Threat Hunting Phishing Analysis Playbook Development MTTR Reduction
Detection & Query
XQL (Cortex) CrowdStrike QL (CQL)
Threat Intelligence
MITRE ATT&CK Diamond Model TTP Extraction IOC Enrichment STIX/TAXII Recorded Future OpenCTI
AI in Security
Microsoft Copilot Agent Dev Agentic SOC Workflows Entity Extraction (JSON) LLM-Assisted Triage AI-Generated Reporting
Automation & Scripting
PowerShell Python Power Automate
Log & Network Analysis
Windows Event Logs PCAP Analysis Wireshark Network Traffic Monitoring
Malware & Forensics
Malware Analysis Memory Forensics (Volatility) Sysinternals Suite
Security Tools
Cortex XDR/XSIAM CrowdStrike Falcon Okta Clearswift DLP Proofpoint Seceon Nmap Snort
Identity & Access
Okta SSO Configuration API Integrations MFA Policy Management Third-Party App Provisioning
Reporting & Docs
SOC KPIs Incident Reports SOP Creation
Certified Threat Intelligence Analyst EC-Council Earned
Certified Ethical Hacker EC-Council Earned
Certified Detection & Remediation Analyst Palo Alto Networks Earned
Security Operations Professional Palo Alto Networks Earned
CrowdStrike QL Fundamentals I & II CrowdStrike Earned
Intelligence Fundamentals Recorded Future Earned
Certified Forensic & Dark Web Analyst Earned
Certified Incident Handler (ECIH) EC-Council In Progress
01 Context over volume. A single high-fidelity detection is worth a thousand noisy alerts. Intelligence that isn't actionable isn't intelligence. It's overhead.
02 Behavior over indicators. IOCs expire. TTPs persist. Build detections against how adversaries operate, not just the artifacts they leave behind today.
03 Every hunt is a detection in progress. If you found it manually once, automate it. Hunting without engineering output is useful, but incomplete.
04 Understand before you respond. Rushing containment without understanding scope creates gaps. Root cause first, containment second, remediation always.
05 Open. Documented. Operational. Security tooling that lives in one person's head isn't a capability. It's a dependency. Build things teams can run with.
H3AD-X
Threat Intelligence Hub
LIVE
IOC enrichment, artifact extraction, and DNS infrastructure mapping across six tools, managed and BYOK.
OPEN H3AD-X →
H3AD-AI
AI-Assisted Analysis Hub
LIVE
PROMPTVAULT — ready-to-use AI prompts for SOC triage, detection engineering, and threat hunting.
OPEN H3AD-AI →
H3AD-DETECT
Detection Engineering Platform
LIVE
MITRE-mapped detection query arsenal — KQL, Sigma, XQL, organized by tactic, platform, and data source.
OPEN H3AD-DETECT →
H3AD-HUNT
Threat Hunting Platform
LIVE
Hypothesis-driven hunting: ATT&CK-native hypotheses, a pivot graph for infrastructure analysis, and CVE-tied query packs.
OPEN H3AD-HUNT →
H3AD-OPS
SecOps Automation
LIVE
Pre-built triage queries for shift analysts, plus a phishing case tracker that aggregates IOCs automatically.
OPEN H3AD-OPS →
H3AD-DF
Digital Forensics
PLANNED
Registry persistence lookup, memory forensics, and disk artifact analysis. First tools ship here as they're ready.
COMING SOON
H3AD-IR
Incident Response
PLANNED
Structured containment, eradication, and recovery playbooks for active incidents.
COMING SOON
H3AD-LEARN
Security Training Platform
LIVE
Field-focused training across five live domains, from threat hunting to interview prep, sourced from real SOC methodology.
OPEN H3AD-LEARN →