Security Operations · Threat Intel · Threat Hunt
DFIR · Malware Analysis ·
Detection Engineering
Hrushikesh
Badgujar.
Rosh Gadol, not rosh katan. I understand the mission before I execute it.
3YrsSecurity Operations
5YrsCyber Security Field
8Platform
Modules
8Certifications
3Published
Writeups
01 / ABOUT
M.Tech in Cybersecurity from NFSU, with 3 years across in-house and managed SOC environments. On any given
shift, I might be investigating alerts, working with threat intelligence, hunting threats, fine-tuning
detections, looking for automation opportunities, or researching something new.
Somewhere between investigating alerts, hunting threats, and doing the same things repeatedly, I started
building my own tools. The result is H3AD-SEC, a platform for IOC enrichment,
threat hunting, detection engineering, automation, and more.
Rosh Gadol, not Rosh Katan: understand the mission first, then build. The same
principle guides my investigations: understand the context before reaching a conclusion.
Every module in H3AD-SEC exists because it solves something I encountered on shift. Built for the work I
actually do, not for a demo that looks good.
Education
M.Tech Cybersecurity · NFSU
Current Role
Associate Specialist · Concentrix
Approach
Purpose-built tooling, no demos
02 / EXPERIENCE
May 2024 — Present
Current
Associate Specialist
Concentrix Daksh Services India Pvt. Ltd.
MDR/XDR SOC operations: alert triage, threat hunting, detection engineering, and building the automation the job actually needed.
Oct 2023 — May 2024
Trainee Cyber, SOC Analyst
Gramax Cybersec
24x7 SOC monitoring and incident triage, the entry point into everything that came after.
03 / DOMAINS
Security Operations
Alert triage, XDR/EDR monitoring, and SIEM workflows inside a live MDR/XDR SOC
environment.
Threat Intelligence
Tracking adversary infrastructure, TTPs, and campaigns, correlating IOCs into
structured intelligence that feeds every other discipline.
Threat Hunting
Hypothesis-driven hunting across endpoint, network, and identity telemetry, finding
what alerts missed, then codifying it.
Incident Response
Containment, eradication, and recovery for active incidents. Root cause before
remediation, always.
Digital Forensics
Registry, memory, and disk artifact analysis, reconstructing what actually happened on
a compromised endpoint after the alert fires.
Automations
Triage queries, enrichment pipelines, and workflow tooling that remove analyst toil so
teams focus on decisions, not data wrangling.
Detection Engineering
Detection logic built around attacker behavior, not just indicators: Sigma rules, SIEM
tuning, and detection-as-code pipelines.
AI Security
Using LLMs for triage, hunt hypothesis generation, and detection engineering, plus the
prompt-injection and AI-abuse risks defenders now have to cover.
04 / STACK
Security Operations
SOC Monitoring
Alert Triage & Escalation
Incident Response
Threat Hunting
Phishing Analysis
Playbook Development
MTTR Reduction
Detection & Query
XQL (Cortex)
CrowdStrike QL (CQL)
Threat Intelligence
MITRE ATT&CK
Diamond Model
TTP Extraction
IOC Enrichment
STIX/TAXII
Recorded Future
OpenCTI
AI in Security
Microsoft Copilot Agent Dev
Agentic SOC Workflows
Entity Extraction (JSON)
LLM-Assisted Triage
AI-Generated Reporting
Automation & Scripting
PowerShell
Python
Power Automate
Log & Network Analysis
Windows Event Logs
PCAP Analysis
Wireshark
Network Traffic Monitoring
Malware & Forensics
Malware Analysis
Memory Forensics (Volatility)
Sysinternals Suite
Security Tools
Cortex XDR/XSIAM
CrowdStrike Falcon
Okta
Clearswift DLP
Proofpoint
Seceon
Nmap
Snort
Identity & Access
Okta SSO Configuration
API Integrations
MFA Policy Management
Third-Party App Provisioning
Reporting & Docs
SOC KPIs
Incident Reports
SOP Creation
05 / CERTIFICATIONS
Certified Threat Intelligence Analyst
EC-Council
Earned
Certified Ethical Hacker
EC-Council
Earned
Certified Detection & Remediation Analyst
Palo Alto Networks
Earned
Security Operations Professional
Palo Alto Networks
Earned
CrowdStrike QL Fundamentals I & II
CrowdStrike
Earned
Intelligence Fundamentals
Recorded Future
Earned
Certified Forensic & Dark Web Analyst
Earned
Certified Incident Handler (ECIH)
EC-Council
In Progress
06 / OPERATING PRINCIPLES
01
Context over volume. A single high-fidelity detection is worth a
thousand noisy alerts. Intelligence that isn't actionable isn't intelligence. It's overhead.
02
Behavior over indicators. IOCs expire. TTPs persist. Build detections
against how adversaries operate, not just the artifacts they leave behind today.
03
Every hunt is a detection in progress. If you found it manually once,
automate it. Hunting without engineering output is useful, but incomplete.
04
Understand before you respond. Rushing containment without understanding
scope creates gaps. Root cause first, containment second, remediation always.
05
Open. Documented. Operational. Security tooling that lives in one
person's head isn't a capability. It's a dependency. Build things teams can run with.
07 / WRITING
08 / PLATFORM
09 / CONTACT