Skip to content

OPEN TO SOC / DFIR INTERNSHIPS · TOP 5% CYBERDEFENDERS

Manichand Gupta

Security Analyst

Entry-level Security Analyst investigating threats through a self-built SOC lab — SIEM alert triage, malware and phishing analysis, mapped to MITRE ATT&CK.

analyst@meerut:~
SCROLL

SECTION 02 / ABOUT

Analyst behind the glass

Entry-level Security Analyst based in Meerut, UP, currently pursuing a BCA in Cloud & Cybersecurity (2024–2027) at IIMT University. Builds and runs a self-managed SOC lab for hands-on detection and monitoring practice, and develops independent security tools for malware and phishing analysis. Comfortable across SIEM, IDS/IPS, endpoint monitoring, network analysis, and DFIR tooling.

Color shifts by section, mapped to Defense-in-Depth layers — perimeter to data.

KC7
Top 1%
Elite Ranking
Top 1% tier of 157,000 players on the KC7 profile ↗
SOC Operations
0
Alerts Triaged
End-to-end triage in a self-built production SOC pipeline
Threat Intelligence
0
YARA Signatures
Aggregated across 40+ threat intel feeds and source repositories
CyberDefenders
Top 5%
Global Ranking
Verified top 5% of Blue Team analysts on CyberDefenders profile ↗
Research
0
Write-ups Published
Published DFIR investigation write-ups with IOCs mapped to ATT&CK

SECTION 02A / DEFENSE IN DEPTH

Layers I work in

Network layer

SIEM correlation, traffic inspection, and protocol-level threat detection

Wazuh Microsoft Sentinel Splunk Elastic Stack Wireshark tcpdump Nmap

Click any ring · Tab + Enter works too.

PERIMETER NETWORK ENDPOINT APP DATA

SECTION 03 / EXPERIENCE

Hands on the queue

Self-Built SOC Detection & Monitoring Lab

Independent

FEB 2026 — PRESENT
  • Watched and analyzed security alerts from Wazuh SIEM and Suricata IDS across a multi-VM lab
  • Triaged 150+ alerts — checked indicators, correlated logs, flagged real security incidents
  • Wrote incident notes covering IOCs, severity level, and next steps for escalation
  • Ranked alerts by priority and mapped them to MITRE ATT&CK techniques
Wazuh Suricata Sysmon MITRE ATT&CK

SECTION 03A / SOC LAB ENVIRONMENT

The environment I built

Attack and defense VMs with SIEM, IDS, and endpoint monitoring.

SIEM Wazuh IDS/IPS Suricata TARGET Windows TARGET Linux ATTACKER Kali

Wazuh SIEM

Central Log Management

Central log aggregation and alert triage. Collects Sysmon events from Windows and auditd logs from Linux. Correlates across endpoints to detect lateral movement and persistence.

Log AggregationAlert TriageCorrelation

5

VMs

3

Tools

150+

Alerts

SECTION 04 / SKILLS & TOOLS

The toolkit

SECTION 05 / MITRE ATT&CK

Mapped to the matrix

Detection coverage across 14 MITRE ATT&CK tactics, full kill-chain — open on desktop for the interactive matrix.

SECTION 06 / PROJECTS

Projects built

Tools I've built and investigations I've documented — each mapped to real attacker techniques.

PROJECT 01 / 05
MALWARE TRIAGE

Malware
Analyzer

Malware triage tool scanning PE, ELF, Mach-O, APK, Office, PDF, scripts, and archives via a Flask/WebSocket dashboard. 2,778 YARA rules from 40 sources. Connects VirusTotal, Hybrid Analysis, Tria.ge, and FileScan.io with live scan progress. Drop a file — or a whole folder — and the queue triages everything in one pass, streaming verdicts to the browser as each engine reports back. Verdicts arrive with matched rules and engine reports side by side, so one screen answers the first triage question. Every scan leaves a shareable record you can revisit later.

Challenge: Manual triage across many file formats is slow — analysts jump between separate tools for each type.
  • Multi-format static analysis: PE, ELF, Mach-O, APK, Office, PDF, scripts, archives
  • 2,778 YARA rules aggregated from 40 intel sources
  • Live WebSocket scan queue with per-file verdicts
  • Multi-engine reputation lookup: VirusTotal, Hybrid Analysis, Tria.ge, FileScan.io
YARA Flask WebSocket VirusTotal
GitHub ↗
PROJECT 02 / 05
T1566 PHISHING

Phishing Mail
Detector

11-step Flask tool validating SPF, DKIM, DMARC, and ARC to catch spoofed emails. Brand-check system covering ~50 commonly faked brands plus QR-code (quishing) detection. ~40-signal risk-scoring model mapped to MITRE ATT&CK T1566. Paste any raw email or .eml and get a full header breakdown, an impersonation verdict, and plain-English reasoning for every signal — evidence an analyst can act on, not a black-box score. Results are structured for handoff — each failed check links straight to the header evidence behind it.

Challenge: Spoofed and brand-impersonating emails pass casual inspection; authentication results are buried in headers most users never read.
  • 11-step header validation: SPF, DKIM, DMARC, ARC chain
  • Impersonation checks against ~50 commonly faked brands
  • QR-code (quishing) detection inside message bodies
  • ~40-signal scoring model mapped to MITRE ATT&CK T1566
SPF/DKIM/DMARC T1566 Flask QR Detection
GitHub ↗
PROJECT 03 / 05
EVTX FORENSICS

Event Analyzer
Web

Fast, analyst-first Windows EVTX viewer with built-in IOC extraction, Sigma rule matching, and MITRE ATT&CK mapping. Upload one or many .evtx files, filter by event ID/channel/provider, bookmark events, take notes, and export results. Drag in a full event dump and pivot instantly — jump to matched Sigma hits, correlate extracted IOCs, and build the case notes as you go. One search box covers events, IOCs, and notes, so the pivot from timeline to evidence stays under a minute. Results export cleanly for case notes and reports.

Challenge: Windows EVTX files are cumbersome to parse manually; analysts need a fast viewer with built-in intel enrichment in one interface.
  • Parallel multi-file .evtx ingestion and indexing
  • IOC extraction with hash, domain, and IP correlation
  • Sigma rule matching with MITRE ATT&CK technique mapping
  • Bookmarks, analyst notes, and exportable case output
EVTX Parsing Sigma Rules IOC Extraction Vue 3
GitHub ↗
PROJECT 04 / 05
DFIR REPORTS

Investigation
Portfolio

Real phishing, malware, and network attack investigations with detailed reports — IOC extraction and MITRE ATT&CK mapping. Full case log in Field Reports below. Seven published write-ups so far. Each report follows the same SOC cadence — scope, timeline, evidence, IoCs, detection gaps, and recommendations — so every conclusion is reviewable end to end. The library keeps growing as each new lab case gets written up in the same format. Every report is written to be reviewed end to end, with the full artifact trail attached.

Challenge: Lab skills are invisible without documented, reviewable investigations written the way a real SOC writes them.
  • Seven published investigation write-ups and counting
  • IOC extraction with hash, domain, and IP correlation
  • MITRE ATT&CK technique mapping per case
  • Detection-gap analysis and remediation guidance
IOC Extraction ATT&CK Mapping Wazuh Suricata
GitHub ↗
PROJECT 05 / 05
THREAT INTELLIGENCE

Threat
Sentry

Real-time threat intelligence aggregator pulling from multiple open-source feeds — URLhaus, ThreatFox, AlienVault OTX, and AbuseIPDB. Correlates indicators, surfaces attacker infrastructure, and maps IoCs to MITRE ATT&CK techniques. Indicators are normalized, deduplicated, and confidence-scored, so campaign infrastructure stands out from feed noise instead of drowning in it. Related indicators are grouped into campaigns, turning the raw feed into attacker storylines. The dashboard surfaces the infrastructure behind each campaign.

Challenge: Threat intel feeds generate massive noise. Analysts need correlation, dedup, and ATT&CK mapping — not a raw feed reader.
  • Live ingestion from URLhaus, ThreatFox, OTX, and AbuseIPDB
  • Cross-feed normalization and deduplication
  • Confidence scoring with attacker-infrastructure grouping
  • MITRE ATT&CK technique mapping on correlated indicators
Threat Intelligence IOC Correlation ATT&CK Mapping Flask
GitHub ↗
01 / 05 PROJECTS

SECTION 07 / FIELD REPORTS

Case files

Real investigations and CTF walkthroughs — from phishing campaigns to RAT analysis, documented step by step.

CASE-2026-001

Job Phishing Campaign — Impersonating Naukri.com

Social engineering · Advance-fee job scam

Read report →
CASE-2026-002

Storm-2949: How One Cloud Account Led to a Full Enterprise Breach

Cloud compromise

Read report →
CASE-2026-003

AI Helpdesk Compromise Leading to Workstation Breach (HackTheBox)

Artifact triage

Read report →
CASE-2026-004

Yellow Cockatoo RAT “Jupyter’s Bro” (CyberDefenders)

RAT analysis

Read report →
CASE-2026-005

PoisonedCredentials (CyberDefenders)

LLMNR/NBT-NS poisoning · NTLMv2 credential capture

Read report →
CASE-2026-006

Stealc Infostealer (Oski Lab) (CyberDefenders)

Sandbox/C2 analysis

Read report →
CASE-2026-007

WebStrike (CyberDefenders)

Web attack investigation

Read report →
All write-ups on Medium

SECTION 07A / LIVE ACTIVITY

Pulled live

Fetched client-side from the GitHub API and Medium RSS at page load — not hand-written cards. If a network fetch fails, the block below says so instead of faking it.

GitHub — recent activity

FETCHING github.com/EclipseManic …

Medium — latest write-ups

FETCHING eclipsemanic.medium.com …

SECTION 08 / CREDENTIALS

Proof of work

Certifications

  • Microsoft Azure Cloud Administration

    EICT, IIT Kanpur · Verify ↗

    DEC 2025
  • Linux Administration with Scripting

    EICT, IIT Kanpur · Verify ↗

    JUL 2025
  • AWS Cloud Fundamentals

    EICT, IIT Kanpur · Verify ↗

    DEC 2024
  • Google Cybersecurity Professional Certificate

    Coursera · Verify ↗

    JUL 2025
  • IBM Cybersecurity Analyst

    Coursera · Verify ↗

    JUL 2025

Education

Bachelor of Computer Application — Cloud & Cybersecurity

IIMT University, Meerut

2024 — 2027
IN PROGRESS

Focus areas

Cloud Security SOC Operations DFIR Threat Detection

Open to SOC / DFIR internships

Manichand Gupta

Security Analyst

I investigate what others miss — every alert triaged, every log correlated, every threat mapped to how it actually happened.

Top 1%Verify ↗KC7KC7 · of 157,000 players
SOC Operations150+Alerts triaged
CyberDefendersTop 5%CyberDefenders ranking
Threat Intel2,778YARA rules
ATT&CK14ATT&CK tactics
Research7Write-ups published

01 — Background

Analyst behind the glass

Entry-level Security Analyst based in Meerut, UP, pursuing a BCA in Cloud & Cybersecurity (2024–2027) at IIMT University. Comfortable across SIEM, IDS/IPS, endpoint monitoring, network analysis and DFIR tooling.

Feb 2026 — Present

Self-Built SOC Detection & Monitoring Lab

Independent

  • Watched and analysed alerts from Wazuh SIEM and Suricata IDS across a multi-VM lab
  • Triaged 150+ alerts — checked indicators, correlated logs, flagged real incidents
  • Wrote incident notes covering IOCs, severity and escalation steps
  • Ranked alerts by priority and mapped them to MITRE ATT&CK techniques

Education

BCA — Cloud & Cybersecurity IIMT University, Meerut 2024 — 2027 · in progress
Download Resume

02 — Inside the lab

The home lab I worked on

A self-managed SOC lab — Wazuh SIEM and Suricata IDS across attack and defense VMs — built to generate, catch and investigate real alerts end to end. Five layers deep, perimeter to data.

03 — Selected work

Projects I Built

04 — Credentials

Certifications

05 — Field reports

Case files

  1. CASE-2026-001 Job Phishing Campaign — Impersonating Naukri.com Social engineeringAdvance-fee job scam
  2. CASE-2026-002 Storm-2949: How One Cloud Account Led to a Full Enterprise Breach Cloud compromise
  3. CASE-2026-003 AI Helpdesk Compromise Leading to Workstation Breach Artifact triageHackTheBox
  4. CASE-2026-004 Yellow Cockatoo RAT “Jupyter’s Bro” RAT analysisCyberDefenders
  5. CASE-2026-005 PoisonedCredentials LLMNR/NBT-NS poisoningCyberDefenders
  6. CASE-2026-006 Stealc Infostealer — Oski Lab Sandbox / C2 analysisCyberDefenders
  7. CASE-2026-007 WebStrike Web attack investigationCyberDefenders
All write-ups on Medium ↗

06 — Contact

Let’s investigate together

Open to SOC / DFIR internships and junior analyst roles. If you have alerts, I have eyes.

manichand.gupta.contact@gmail.com

Meerut, UP · © 2026 Manichand Gupta