H3AD-SEC · whoami
Hrushikesh Badgujar
SOC Analyst · Detection Engineer · H3AD-SEC
h3ad@h3ad-sec ~ bash
root@h3ad-sec:~$
whoami
Hrushikesh Badgujar
/
SOC Analyst · Detection Engineer · H3AD-SEC
root@h3ad-sec:~$
cat mission.txt
Operationalizing threat intelligence across the full defensive spectrum. Raw IOC to root cause, hypothesis to detection rule.
root@h3ad-sec:~$
domains --list
Threat Intelligence ·
APT Tracking ·
Detection Engineering ·
DFIR ·
Threat Hunting ·
SOC Automation
root@h3ad-sec:~$
status --self
online & building
root@h3ad-sec:~$
7MODULES
25+TOOLS LIVE
6DOMAINS
2026ACTIVE BUILD
Intelligence without action is noise.
Detection without context is blind.
Response without understanding is guesswork.
H3AD-SEC closes the gap. Raw threat data to operational defense, hypothesis to detection rule.
ABOUT
M.Tech in Cybersecurity from NFSU. 2.5+ years in MDR/XDR SOC operations, treating detection engineering, threat intelligence, and incident response not as separate tracks but as the same job.
H3AD-SEC is where that work compounds.
My work sits at the intersection of threat intelligence, detection engineering,
and incident response, treating them as inseparable disciplines of the same operational reality.
I focus on attacker behavior at the TTP level, translating that understanding
into detection logic that survives real-world noise,
and building tooling that makes a lean SOC punch above its weight.
Every module in this platform is purpose-built.
No demos for demos' sake. If it's here, it solves a real problem in cyber defense operations.
EXPERIENCE
May 2024 — Present
Current
Associate Specialist - Security Operations
MDR and in-house SOC environment. XDR alert triage, CTI-driven threat hunting, and detection engineering. False positive reduction, detection rule tuning, and SOC automation. IAM operations support.
Oct 2023 — Apr 2024
Cyber Security Intern · MDR Operations
MDR environment. 24x7 SIEM/EDR/CASM/WAF monitoring. Alert investigation, incident triage, and SOC process improvement.
DOMAINS
Threat Intel & APT Tracking
Tracking adversary infrastructure, TTPs, and campaigns. Correlating IOCs into structured intelligence that feeds every other discipline.
Detection Engineering
Writing detection logic that reflects attacker behavior, not just indicators. Sigma rules, SIEM tuning, and detection-as-code pipelines.
DFIR & Malware Analysis
From triage to root cause. Artifact collection, memory forensics, and malware behavior analysis to understand exactly what happened.
Threat Hunting
Hypothesis-driven hunting across endpoint, network, and identity telemetry. Finding what alerts didn't catch, then codifying it.
SOC & SecOps Automation
Triage queries, enrichment pipelines, and workflow tooling. Removing analyst toil so teams focus on decisions, not data wrangling.
Platform Building
H3AD-SEC is an operational cyber defense platform in active development. Each module ships real capability, not demos.
STACK
EDR / XDR
Cortex XDR
XSIAM
CrowdStrike Falcon
CTI
Recorded Future
OpenCTI
Email / DLP
Proofpoint
Clearswift DLP
Forensics
Volatility
Sysinternals
Wireshark
Nmap
Snort
Query / Detection
Cortex XQL
CrowdStrike QL
Sigma
Scripting
PowerShell
Python
Power Automate
Frameworks
MITRE ATT&CK
Diamond Model
CERTIFICATIONS
EC-Council
Certified Threat Intelligence Analyst
Earned
EC-Council
Certified Ethical Hacker
Earned
Palo Alto Networks
Certified Detection & Remediation Analyst
Earned
CrowdStrike
CrowdStrike QL Fundamentals I & II
Earned
Recorded Future
Intelligence Fundamentals
Earned
Certified Forensic & Dark Web Analyst
Earned
EC-Council
Certified Incident Handler (ECIH)
In Progress
WRITING
OPERATING PRINCIPLES
01
Context over volume. A single high-fidelity detection is worth a
thousand noisy alerts. Intelligence that isn't actionable isn't intelligence. It's overhead.
02
Behavior over indicators. IOCs expire. TTPs persist. Build detections
against how adversaries operate, not just the artifacts they leave behind today.
03
Every hunt is a detection in progress. If you found it manually once,
automate it. Hunting without engineering output is useful, but incomplete.
04
Understand before you respond. Rushing containment without understanding
scope creates gaps. Root cause first, containment second, remediation always.
05
Open. Documented. Operational. Security tooling that lives in one
person's head isn't a capability. It's a dependency. Build things teams can run with.
PLATFORM
H3AD-X
IOC enrichment across 11 sources. Deep IP analysis, artifact extraction, DNS infrastructure mapping.
Live
H3AD-AI
Seven AI tools for SOC workflows: runbooks, query generation, FP analysis, ATT&CK mapping, timeline reconstruction, malware analysis, and prompt library.
Live
H3AD-DETECT
MITRE-mapped detection query arsenal. KQL, Sigma, XQL, organized by tactic, platform, and data source.
Live
H3AD-HUNT
Hypothesis-driven hunting. Pivot graph for infrastructure analysis, CVE-tied query packs, structured hunt methodology.
Live
H3AD-OPS
Pre-built triage queries across auth, network, endpoint, and cloud. Built for shift analysts.
Live
H3AD-DF
Forensic analysis, artifact recovery, and memory analysis workflows.
Live
H3AD-IR
Structured containment, eradication, and recovery playbooks for active incidents.
Live
H3AD-LEARN
Modular security learning hub. Threat hunting and LOLBAS methodology, chapter by chapter.
Live
CONTACT
Collaboration, research exchange, threat intel sharing.
↗
CONTACT