My Background
Personal Profile
Experienced CYSA+, CCFE Certified security professional specializing in incident investigations, and mitigation. Proven ability to lead complex security incident investigations, analyse and interpret data to evaluate breaches, and communicate technical findings effectively to senior-level audiences. Proficient in conducting investigations and providing comprehensive solutions to restore trust and protect client assets.
​
Successfully completed the SANS 508, SANS 500 (2020 edition) Course (Not certified)
​
With Multi Tools experience:
EDR/MDR : - Sentinel One(MDR), Qualys EDR, MDFE, Carbon Black
XDR : - Bit Defender, CrowdStrike (Falcon).
CDR : - Obsidian
SIEM : - Microsoft Sentinel (IR Purposes)
Log Analysis : - Chainsaw, Hayabusa, LogParser, EvtxECmd.
DFIR : - Velociraptor, Redline, FTK Imager, Cyber triage, OS Forensics, Magnet Axiom, Vound Intella
Memory Analysis :- Volatility 3, WinPmem, MemProc5
File Recovery :- Photorec
Eric Zimmerman :- Kape, AmcacheParser, ShimCache parser, JLECmd, LECmd, SBECmd, Registry Explorer (All tools)
TimeLine creation :- MFTECmd, Log2Timeline (Plaso)
MS365 Analysis :- Microsoft extractor suite, Analyzer suite
Quick Guides (Created by me)
Intrusion detection Cheat sheet
Incident Handling Checklist
FTK Imager Based Imaging
Windows Artifact Analysis
Post-Attack Remediation Steps
for Windows, Linux, Mac:
Linux IR Cheatsheet
Common (Win) Artifact Paths
Important Registry Collection
Lateral Movement Analysis
USB Forensic
Email Analysis
Incident response/analysis script created by me
Threat Intelliegnce for Ransomware DLSs
MAC IR Cheatsheet
Curriculum Certifications
Professional Credentials
2017-2020
Guru Nanak dev university, Amritsar
Degree:- Bachelor of Computer Application.
​
Went through Multiple courses
Like C, C++, Python, DBMS, JAVA, and Information technology, Digital electronics, Operatingsystem, Computer networks, Data structure, Web Technologies
05/2024 - Present
Company Name:
Ankura Consulting Group
Designation :- Cybersecurity Incident response, Associate
-
Led complex security incident investigations.
-
Analyzed data to evaluate breaches and information exfiltration.
-
Conducted Incident Response procedure on Affected clients
-
Communicated findings and recommendations to senior clients.
-
Managed BEC incident responses and performed root cause analysis.
-
Drafted comprehensive incident reports with remediation steps.
05/2021 -09/2022
Designation :- Cyber - Operation Executive
​
-
Monitored security alerts, conducted log analysis.
-
Collaborated with senior cybersecurity professionals.
-
Documented security incidents
-
Ensured effective cybersecurity operations.
-
Stayed updated on latest threats.
-
Actively handled security events, security awareness.
Company Name:
Infosys Ltd
09/2022 - 05/2024
Company Name:
ConnectWise
Designation :- Cyber Security Analyst L2
​
-
Guided clients through incident response.
-
Advised clients on security strategies.
-
Handled various cybersecurity threats.
-
Assisted in addressing findings from scans and tests.
-
Managed event sets for threat resolution.
-
Monitored systems for breaches and activity.