Security Operations • Detection Engineering • Threat Intelligence

Aryan Hirapara

Cybersecurity graduate student building SOC workflows, detection logic, automation, and analyst-friendly investigation pipelines.

Focused on Wazuh, MITRE ATT&CK mapping, IOC enrichment, incident response, malware analysis, and Python-based security automation.

About

SOC-focused profile

Cybersecurity graduate student with hands-on experience in SIEM administration, detection engineering, SOC processes, threat intelligence, malware traffic analysis, and incident response. Comfortable working across log analysis, PCAP investigation, custom rule authoring, IOC enrichment, and security automation.

I build practical security workflows that connect telemetry, detections, and response steps clearly enough for analysts to trust and use in real investigations.

Experience

Security operations exposure

Jun 2026 - Present Hybrid

Infosec Intern

CyberOps Infosec LLP

  • Contributing to information security operations, threat analysis, and incident investigation.
  • Supporting SOC processes, log analysis, and security monitoring in a live professional environment.
Jul 2024 - Sep 2024 Remote

Cyber Security Intern

Centre for Development of Advanced Computing (C-DAC)

  • Assisted in security analysis and structured reporting within a government R&D environment.
  • Supported log data analysis and security best-practice integration across development workflows.

Projects

Detection-driven lab work

2026

NetTrace - Malware Traffic Analysis Platform

Built a Python-based malware traffic analysis platform that analyzes offline PCAP files, extracts network indicators, maps findings to MITRE ATT&CK, and generates analyst-ready reports.

  • Extracted DNS, HTTP, TLS SNI, IP flow, URL, domain, and public IP IOCs.
  • Detected DGA-like domains, beaconing, suspicious user agents, downloads, unusual ports, high-frequency flows, and long TLS sessions.
  • Validated on 5 real malware traffic samples with packet-level Wireshark evidence and 53 passing tests.
GitHub

2026

SOC Automation Lab

Built an end-to-end SOC pipeline with Wazuh, n8n, MITRE Caldera, and Velociraptor for detection engineering and automated incident response.

  • Created custom detections mapped to MITRE ATT&CK.
  • Triaged alerts from live adversary simulations.
  • Automated IOC enrichment through Python workflows.
GitHub

2026

Malware Analysis

Analysed malware samples in an isolated environment and converted observed behavior into actionable threat intelligence.

  • Extracted IOCs from process, file, registry, and network layers.
  • Mapped observed techniques to MITRE ATT&CK.
  • Authored a YARA detection rule and intelligence report.
GitHub

2026

Malware Behavior to Detection Pipeline

Developed a Python pipeline that ingests sandbox reports, extracts malicious behavior, maps it to MITRE ATT&CK, and generates detection content.

  • Produced Sigma and Wazuh detections from behavior-driven mappings.
  • Added explainability metadata from behavior to final rule output.
  • Included validation, scoring, reporting, and 89 automated pytest tests.

Education

Academic background

National Forensic Sciences University

MSc in Digital Forensics & Information Security

Aug 2025 - Present • Gandhinagar • CPI 8.05

Gujarat University

BSc in Computer Science

Oct 2021 - Jul 2024 • Ahmedabad

Skills

Technical capability

SIEM / SOC

Wazuh SIEM, alert triage, incident response, SOC workflows, log correlation, false-positive tuning.

Detection Engineering

MITRE ATT&CK, Sigma rules, correlation rules, behavioral detections, use-case development.

Threat Intelligence

IOC enrichment, MISP, MITRE ATT&CK mapping, threat hunting, analyst reporting.

Scripting

Python, Scapy, PyYAML, Jinja2, ReportLab, Pytest, PowerShell, and Bash.

Log Analysis

Windows Event Logs, Sysmon, ELK Stack familiarity, Splunk familiarity.

Network Traffic Analysis

PCAP analysis, Wireshark, DNS/HTTP/TLS review, IOC extraction, beaconing, and DGA indicators.

Contact

Let’s connect