AG
akg@soc-terminal: bash
INITIALIZING... 0%
[ SECURITY PROTOCOLS ACTIVE ]
Active now
🕐--:-- IST · Vadodara, India
📦 Last commit: checking...
⚡ 60-Second Recruiter View

Everything you need to know about Aditya, in one screen. No scrolling required.

Aditya Kumar Goswami
Associate SOC Engineer at Investis Digital · Vadodara, India
10K+
Alerts Resolved
9.47 CGPA
University Gold Medallist
40+
Certifications
18 min
AI-Augmented MTTD
TOP SKILLS
SOC Operations DFIR Cloud Security (AWS) AI-Augmented Detection VAPT
Currently triaging enterprise security alerts at Investis Digital with a 30% false-positive reduction via ML tuning. Combines hands-on Blue Team operations with AI-augmented workflows, not just using AI tools, but building automation around them.
Contact → ↓ Download CV
✓ Verification Checklist
Open to Opportunities
📄 Resume Preview: Aditya Kumar Goswami
Aditya Kumar Goswami
Associate SOC Engineer · Cybersecurity Professional
📧 akgoswami185@gmail.com 📞 +91 97262 79007 📍 Vadodara, Gujarat 🔗 linkedin.com/in/aditya-kumar-goswami
Professional Summary
Dedicated SOC Engineer with 2+ years in enterprise security operations. Expert in blue team operations, AI-augmented threat detection, VAPT, DFIR, and cloud security across AWS environments. Gold Medalist with 9.47 CGPA in Forensic Science.
Experience
Associate SOC Engineer: Investis Digital Pvt Ltd
May 2024 – Present · Full-Time · Vadodara
  • Resolved 10,000+ security alerts using AI-assisted triage and Kibana SIEM
  • Reduced false positives by 30% via ML-based WAF rule tuning on Cloudflare
  • Conducted VAPT using Burp Suite, Nmap, Nessus across enterprise web apps
  • Monitored cloud infrastructure (AWS EC2, S3, CloudWatch) for security events
Education
B.Sc. Forensic Science (Cyber Forensics): 2021–2024
CGPA: 9.47/10 · 🥇 Gold Medalist
Core Skills
SOC OperationsSIEM (Kibana/Wazuh) Incident ResponseVAPT DFIRAWS Security Cloudflare WAFPython Automation ISO 27001AI-Augmented SOC
Certifications (40+)
Blue Team Junior Analyst · SOC L1 & L2 (THM) · Multi-Cloud Blue/Red Team Analyst · ISO 27001:2022 Lead Auditor · (ISC)² CC · AWS Cloud Practitioner · CEH · DFE · and 32 more
↓ Download PDF
📅 Book a Free Discovery Call
📅
Calendly Integration Ready

Add your real Calendly link to activate live booking. Until then, reach out directly and a slot will be confirmed by email within a few hours.

✉ Email to Schedule Message on LinkedIn
AdityaSec
Associate SOC Engineer · Cybersecurity Consultant
akgoswami185@gmail.com
+91 97262 79007
Vadodara, Gujarat, India
Service Proposal
Prepared for: General Inquiry
Overview
What's Included
📄 Generate a Proposal

Pick a service and (optionally) a name, a one-page proposal will be ready to print or save as PDF.

🎨
247 profile views
🎬 60-Second Introduction: Aditya Kumar Goswami
🎥

Introduction Video

Upload your 60-second intro video here. This modal is wired up and ready.
Replace this placeholder with a <video> or YouTube embed.

Recommended: Record a 60-second Loom or screen-recorded video introducing yourself, your skills, and what you bring to a team. Recruiters spend 7s on resumes, give them 60s of you.

19 jump sections · T terminal · R resume · ? help
About Mistakes I've Learned From A Day in My SOC Career Timeline Skills AI & Automation Live Security Tools Case Study Threat Dashboard CTF Achievements Trophy Wall Services Certifications GitHub Blog Resources & Extras Learning Roadmap Testimonials Contact
Available for Opportunities · Vadodara, India

Securing the Enterprise.
Powered by AI.

Blue Team specialist with 2+ years in enterprise SOC, combining deep cybersecurity expertise with AI-driven automation to detect threats faster, respond smarter, and secure at scale.

Get In Touch → ↓ Download CV
🛡️
10K+
Alerts Resolved
🏅
9.47 CGPA
Gold Medallist 🥇
18 min
MTTD (AI-augmented)
📜
40+
Certifications
akg@portfolio: interactive terminal
akg@portfolio:~$
Aditya Kumar Goswami
AK
Aditya Kumar Goswami
Associate SOC Engineer · IDX
Status● Active & Available
AI ProficiencyAdvanced
ClearanceAvailable on Request
SOC Operations90%
AI & Automation85%
Cloud Security85%
Blue TeamDFIRAI SOCAWS
Before You Scroll Further

Not Your Typical SOC Resume

You've seen hundreds of cybersecurity profiles that look the same. Here's what's actually different about this one.

Typical SOC Profile
This Portfolio
Skills section
A bullet list of tools
Live security tools you can actually use, not just claims on a page
Proof of work
"Experienced in incident response"
A real anonymized case study, walked through step by step
AI claims
"Familiar with AI tools"
A working AI-assisted chatbot, phishing analyser, and malware report generator, try them above
Certifications
A static list of acronyms
40+ certs with one-click verification, holographic cards, filterable by category
Engagement
PDF you download once and forget
Live GitHub activity, real-time status, and a portfolio that updates itself
About

Enterprise Security.
AI-Augmented Operations.

🥇

University Gold Medallist: CGPA 9.47 / 10.0

Awarded the highest academic distinction in B.Sc. Forensic Science (Cyber Forensics), graduating batch of 2024. Ranked #1 in the programme, combining academic excellence with hands-on industry practice from Day 1.

I am a dedicated cybersecurity professional with 2+ years of hands-on experience in enterprise Security Operations Centers, specializing in blue team operations, threat detection, and incident response.

At Investis Digital, I leverage both deep security expertise and modern AI tools to monitor, detect, and respond to threats across cloud and on-prem infrastructure, faster than traditional methods allow.

My approach blends human analytical judgment with AI-assisted automation: LLMs for threat report generation, AI-powered SIEM anomaly detection, and scripted workflows to reduce MTTR and eliminate alert fatigue.

SOC OperationsBlue Team Threat DetectionVAPT DFIRGRC Cloud SecurityAI-Augmented SOC
10K+
Alerts Resolved
25%
Alert Volume Reduced
30%
False Positives Cut
40+
Certifications
My Story

Why Cybersecurity?

I didn't fall into cybersecurity by accident. I went looking for the field where curiosity is actually an asset, not a liability. Every other discipline I studied rewarded following the rules. Security rewards finding where the rules break.

My first real moment came early, watching a live phishing campaign unfold against a college network and realizing how fragile "secure" systems actually are when humans are involved. That gap between what a system promises and what it actually does became the thing I chased for the next several years, through 40+ certifications, a Gold Medal, and now a daily seat in an enterprise SOC.

What keeps me here isn't the alerts or the dashboards, it's the asymmetry. One attacker needs one mistake. I need to be right every time. AI is finally tilting that asymmetry back in the defender's favor, and I want to be one of the people who builds that future, not just reacts to the one we have.

Operating Philosophy

"I don't wait for alerts. I go looking for threats, and I let AI carry the noise so I can focus on the signal."

Every system in front of me is either compromised, about to be, or successfully defended, there is no neutral state in security.

Honest Reflection

Mistakes I've Learned From

Everyone shows their wins. Here are two things that went wrong early on, and what actually changed because of them.

01
I once closed an alert as a false positive that wasn't.
Early in my SOC career, I dismissed a low-severity alert, odd PowerShell execution on a single endpoint, because it matched a known noisy pattern from an IT script. It wasn't. It was the first stage of a dropper that sat dormant for several days before attempting lateral movement. We caught it during a routine threat hunt, not because the alert worked as intended.
What changed: I stopped trusting pattern-matching alone for triage decisions. Now any alert involving script execution gets a process-tree check before closure, regardless of how "normal" the parent process looks. That single habit has caught two more genuine threats since.
02
I over-tuned a detection rule and created a blind spot.
Trying to cut down false positives on a noisy brute-force detection rule, I added a condition requiring failed attempts to come from a single source IP within a tight time window. It worked, false positives dropped sharply. It also meant a slow, distributed credential-stuffing attempt using rotating IPs sailed through undetected for almost a week.
What changed: I learned that false-positive reduction and detection coverage are a trade-off, not a free win, every tightened rule needs a corresponding compensating control. Now any rule change goes through a "what would this miss?" review before deployment, not just "does this reduce noise?"
Behind the Dashboard

A Day in My SOC

What "SOC Engineer" actually looks like, hour by hour, for anyone who's never sat behind the glass. A real day touches a dozen tools, three security domains, and AI runs through almost all of it.

07:45
Shift Handover & Overnight Triage
Review overnight alerts queued across Kibana, Wazuh, and Microsoft Sentinel. Cross-check Suricata and Sysmon telemetry, prioritize by severity using risk-based alerting, and flag anything needing escalation before the team standup.
KibanaWazuhSentinelSuricataSysmon
08:30
🌅
Morning Planning, AI-Assisted
Before diving into tickets, I ask Gemini and ChatGPT to summarize overnight CVE disclosures relevant to our stack and draft a rough priority order for the day. Five minutes of AI delegation that used to take 30 minutes of manual reading.
GeminiChatGPTCVE Feeds
09:15
🔍
Proactive Threat Hunt
Hunt for IOCs and anomalous behavior patterns automated rules might miss, mapped against MITRE ATT&CK TTPs. Correlate IOC/IOA-based detections across SumoLogic and Log360, building or refining use-cases as patterns emerge.
MITRE ATT&CKSumoLogicLog360
10:30
☁️
Cloud & WAF Posture Review
Check Azure and AWS (EC2, S3, CloudWatch, IAM) for drift, review Defender XDR alerts, and audit Cloudflare WAF and Akamai rules. Update IP blacklisting and DDoS mitigation thresholds as new threat intel comes in from Site24x7.
AzureAWSDefender XDRCloudflare WAFAkamai
11:30
⚙️
SIEM Rule & Correlation Tuning
Refine correlation rule logic and Wazuh ML baselines to cut false positives without losing real signal. This is where the 30% FP reduction came from, scripted and validated using Python and PowerShell before deployment.
Wazuh MLPythonPowerShell
12:30
🥗
Lunch, AI Runs in the Background Too
Even off the clock, AI shows up: I'll ask Claude or Gemini to summarize a long article I didn't have time to read, draft a quick reply email, or plan a workout split. Same tools, completely different problem space.
ClaudeGemini
13:15
🤖
AI-Assisted Log Correlation
Use ChatGPT and Gemini to accelerate log correlation across Windows Event Logs, Syslog, firewall, EDR/XDR, proxy, and cloud logs, summarize TTPs, and draft the technical sections of incident reports before I review and tighten them.
ChatGPTGeminiWindows Event Logs
14:15
🛡️
VAPT & Vulnerability Validation
Run targeted scans and manual checks with Nessus, Nmap, Burp Suite, OWASP ZAP, and SQLMap. Validate findings against Metasploit where exploitation needs confirming, then document severity using CVSS-aligned scoring.
NessusNmapBurp SuiteOWASP ZAPSQLMapMetasploit
15:30
🚨
Incident Response, When It's Real
When something real fires, contain, collect evidence with Wireshark and Autopsy, eradicate, and document the timeline in The Hive while it's fresh. Cross-reference indicators against MISP for related campaign activity.
WiresharkAutopsyThe HiveMISP
16:30
📋
GRC & Compliance Work
Rotate into GRC tasks: mapping controls against ISO/IEC 27001:2022, NIST, and CIS benchmarks, checking Bitsight ratings, and updating RCA documentation and tickets in Jira and Confluence for ongoing audits.
ISO 27001NISTCISJiraConfluence
17:30
📊
Reporting & Handover
Compile the day's findings into stakeholder-ready reports using AI to draft the first pass and cut documentation time significantly, update playbooks in The Hive, and brief the next shift on anything still open.
ReportingThe HiveAI Drafting
19:00
📚
Evening: Learning & Side Projects
Most evenings go to certifications, CTF practice, or building small automation scripts. AI shows up again here too, helping me scaffold Python tooling faster or explain a concept I want to go deeper on, this time entirely self-directed.
PythonBashSelf-Study
Career Journey

Interactive Timeline

Drag to explore, click any milestone for details.

2021
B.Sc. Forensic Science
Cyber Forensics Track
🎓 Degree
Apr 2023
Computer Forensic Analyst
Regional Forensic Lab
🔬 Forensics
May 2023
Cybersecurity Analyst
Cyber Octet Pvt Ltd
🛡️ Intern
Nov 2023
SOC Analyst
Chaitanya Cyber Strix
🔍 SOC
Dec 2023
Compliance Intern
Sannibh Technologies
📋 GRC
Dec 2023
Cybersecurity Intern
Cyber Secured India
⚔️ VAPT
2024
Gold Medal: 9.47 CGPA
B.Sc. Graduation
🥇 Gold
2024 to 2026
M.S. Cybersecurity
Postgraduate Degree
🎓 Masters
May 2024 to NOW
Assoc. SOC Engineer
Investis Digital (IDX)
● Current
Skills

Technical Expertise

Skills Radar
Capability Overview

Deep expertise across the full security spectrum, from proactive threat hunting and incident response to cloud security architecture and compliance auditing. AI amplifies every domain.

SOC Operations
Threat Monitoring90%
Incident Response85%
Log Analysis90%
SIEM Management85%
KibanaWazuhSplunkSumoLogicSuricata
VAPT
Web App Security75%
Network Scanning80%
Vulnerability Assessment85%
Burp SuiteOWASP ZAPNmapNessusSQLMap
DFIR
Digital Forensics80%
Incident Investigation85%
Malware Analysis75%
AutopsyFTKThe HiveMISPWireshark
GRC
Compliance Auditing80%
Risk Assessment75%
Policy Development70%
ISO 27001NISTCIS ControlsBitsight
AWS Cloud
AWS Security85%
EC2S3CloudWatchWAFIAM
Azure
Azure Security60%
Virtual MachinesSecurity Center
AI & Automation

AI-Augmented Cybersecurity

I don't just use AI tools, I build with them. This section covers how AI fits into actual SOC workflows, the full toolkit I rely on day to day, and the automation I've built on top of it, including agentic workflows that go beyond simple prompting.

🤖
Why AI in Cybersecurity?
AI doesn't replace the analyst, it amplifies them. I use AI to eliminate noise, surface real threats, generate reports instantly, and automate repetitive tasks, freeing time for strategic defence work.
My AI-First SOC Approach
Every alert I investigate starts with AI-assisted context enrichment. LLMs summarize threat intel, Copilot accelerates detection rule development, and ML anomaly detection catches what rule-based systems miss entirely.
Core AI Platforms I Work With
🧠
ChatGPT & Claude
LLM Analysis & Reporting
Analyze suspicious log patterns, generate incident reports in minutes, summarize threat intel from multiple feeds, draft playbook documentation and explain malware behaviour to stakeholders.
Incident ReportsThreat IntelLog Interpretation
Google Gemini
Multimodal Analysis & Research
Use Gemini's long-context window for analyzing lengthy compliance documents, cross-referencing multiple CVE advisories at once, and multimodal review of screenshots from phishing or alert investigations.
Long-Context AnalysisDocument ReviewMultimodal
📊
AI-Powered SIEM
Anomaly Detection & Correlation
Kibana ML modules and Wazuh AI anomaly detection baselines normal behaviour across thousands of endpoints, surfacing genuine outliers that rule-based systems miss entirely.
Anomaly DetectionUEBAML Correlation
💻
GitHub Copilot
Security Automation & Scripting
Accelerate Python security scripts: automated IOC extraction, log parsing pipelines, API integrations with threat intel feeds, and custom detection rules, all built faster with AI pair programming.
Python ScriptsIOC ExtractionDetection Rules
🔗
n8n Workflow Automation
Agentic & No-Code Automation
Build agentic automation pipelines connecting SIEM alerts, threat intel APIs, and LLM reasoning steps, so routine triage and enrichment runs without me touching it manually.
Agentic AIWorkflow AutomationAPI Orchestration
🦠
VirusTotal AI & SOCRadar
Threat Intelligence & Malware Analysis
AI Code Insight explains obfuscated malware scripts in plain language, while SOCRadar's AI-enriched threat intelligence pinpoints campaign infrastructure faster than manual pivoting.
Malware AnalysisThreat Intel
Where AI Fits in the Detection Lifecycle
🔍
DETECT
AI anomaly detection flags unusual behaviour in SIEM
🧠
ENRICH
LLM pulls IOC context from threat intel feeds automatically
TRIAGE
AI scores severity; analyst reviews high-priority queue only
🛡️
RESPOND
Automated playbook executes containment actions
📋
DOCUMENT
AI generates full incident report & Jira ticket in seconds
Measured Impact
70%
Faster Incident Report Generation with LLMs
30%
Reduction in False Positives via ML Tuning
Faster Detection Rule Dev with Copilot
18min
Mean Time to Detect (down from 4 hrs)
AI & ML Knowledge Base
Prompt EngineeringLLM-Assisted Threat AnalysisML Anomaly DetectionUEBAAI-Powered SIEMAutomated PlaybooksPython Security AutomationNLP for Log AnalysisGitHub CopilotChatGPT API IntegrationAI-Assisted ForensicsGenerative AI ReportingAgentic AI Workflowsn8n AutomationGemini APIRAG Pipelines
AI Tools I Use Daily: Interactive

Click each tool to see exactly how I use it in real SOC workflows.

ChatGPT & Claude: LLM Analysis

I use large language models daily to accelerate incident analysis, generate reports, and summarize threat intelligence in seconds rather than hours.

Summarize MITRE ATT&CK TTPs for a detected threat actor in 60 seconds
Draft post-incident reports from structured notes. 75% time savings
Explain malware behaviour to non-technical stakeholders in plain language
Generate Kibana KQL queries and Sigma detection rules from a description
Cross-reference CVE advisories and build remediation briefings
75%
Reduction in report writing time
60s
Average TTP summary generation
Daily
Active usage in SOC workflow

Gemini: Long-Context & Multimodal Analysis

Gemini's long-context window handles things ChatGPT and Claude conversations sometimes can't hold in one pass, especially when cross-referencing lengthy compliance documents or multiple CVE advisories simultaneously.

Cross-reference 5+ CVE advisories at once for a single patch decision
Review full ISO 27001 policy documents in one pass without chunking
Multimodal review of phishing email screenshots and alert dashboards
Summarize entire incident timelines from raw exported logs
Morning briefing: summarize overnight CVE disclosures before shift starts
1M+
Token context for large documents
Daily
Morning CVE briefing routine
Multimodal
Screenshot & document review

GitHub Copilot: Security Automation

I use Copilot as an AI pair programmer to accelerate Python security scripts, detection logic, and automation tooling, turning hours of coding into minutes.

Automate IOC extraction from raw log files using regex + API calls
Build Kibana alert → Jira ticket automation pipelines
Generate Suricata/Snort rules from threat descriptions
Python scripts for AWS CloudTrail anomaly detection
Accelerate detection rule development 5× over manual coding
Faster detection rule development
Python
Primary automation language
12+
Custom automation scripts built

n8n: Agentic Workflow Automation

I build agentic automation pipelines in n8n that chain SIEM alerts, threat intel API calls, and LLM reasoning steps together, so routine enrichment and triage runs without me manually touching every alert.

Agent pipeline: new alert → auto-enrich IOC via VirusTotal/SOCRadar API → LLM severity scoring → Jira ticket if high-risk
Scheduled agent that pulls overnight CVE feeds, filters by relevance to our stack, and posts a summary to Slack
Multi-step agent for phishing triage: extract URLs → check reputation → LLM verdict → auto-quarantine if malicious
Webhook-triggered workflows connecting Kibana alerts directly to automated response actions
Currently expanding into more autonomous, multi-tool agent chains beyond simple linear workflows
Agentic
Multi-step automation, not just scripts
No-Code
+ custom code nodes where needed
24/7
Triage runs even when I'm offline

AI-Powered SIEM: Kibana & Wazuh

I leverage ML modules in Kibana and Wazuh to baseline normal behaviour across thousands of endpoints, surfacing genuine anomalies that rule-based systems miss.

Kibana ML anomaly detection for user behaviour (UEBA)
Wazuh ML rules reduced MTTD from 4 hours to 18 minutes
Correlated ALB, Cloudflare CDN, and IIS logs to detect coordinated attacks
Built custom dashboards for executive threat visibility reporting
Tuned ML baselines to reduce false positives by 30%
18min
MTTD (down from 4 hours)
30%
False positive reduction
3
Log sources correlated in real-time

SOCRadar: External Threat Intelligence

I use SOCRadar for external threat intelligence enrichment, identifying threat actor infrastructure, tracking campaigns, and enriching IOCs beyond what internal tools surface.

Linked attack IPs to known credential-stuffing-as-a-service groups
Identified 3 additional client targets in the same threat actor campaign
Dark web monitoring alerts for client data exposure
Attack surface management, external asset enumeration
TTP profiling combined with LLM summarization for rapid stakeholder reporting
5min
Full TTP summary generation
Real-time
Threat actor infrastructure tracking
Dark Web
Data exposure monitoring

VirusTotal AI: Malware & IOC Analysis

Daily use for rapid IOC enrichment, scanning suspicious files, URLs, IPs and domains against 70+ AV engines and AI-assisted code analysis during triage.

Rapid hash lookups during alert triage. 30-second IOC enrichment
Sandbox detonation and behaviour analysis for suspicious attachments
URL reputation checks for phishing investigation workflows
AI Code Insight feature to explain obfuscated malware scripts
Pivoting from one IOC to discover related threat actor infrastructure
70+
AV engines in scan pipeline
30s
Average IOC enrichment time
AI
Code Insight for malware analysis
🌐 AI Isn't Just a Work Tool for Me

The same models I use for threat analysis show up everywhere else too: drafting and tightening writing, planning workouts, summarizing long articles I don't have time to read in full, and learning new technical topics faster by asking Claude or Gemini to explain something three different ways until it clicks. Treating AI as one consistent skill rather than a job-specific tool is, I think, exactly why I stay comfortable picking up new AI tools quickly, the underlying habit of delegating well and verifying critically transfers everywhere.

Try It Yourself

Live Security Tools

An AI assistant trained on my background, and a set of genuinely hard technical questions for anyone who wants to test my knowledge directly.

🤖 Ask About Aditya Pre-loaded with resume data

Ask anything about skills, certifications, experience, or how to get in touch. Try one of the suggestions below.

🤖
Hi! I'm an AI assistant trained on Aditya's resume, certifications, and project history. Ask me anything, try a suggestion below to get started.
What certifications does he have? Can he handle AWS security? Can he handle a ransomware incident? How do I hire him? What AI tools does he use?

🧠 Stump Me Direct technical vetting

This isn't a generic chatbot demo, it's a bank of genuinely hard SOC, DFIR, and cloud security questions with real answers. Pick one and judge for yourself.

Select a question above to see the answer
Case Study

Real Incident Deep-Dive

A walk-through of a real enterprise threat I detected, investigated, and resolved, anonymized for confidentiality.

01
Initial Detection
Anomalous WAF traffic pattern triggers Cloudflare alert at 02:14 AM
02
Log Analysis & Triage
Kibana SIEM correlation across ALB, CDN, and IIS logs reveals coordinated attack
03
Threat Intelligence
SOCRadar identifies threat actor infrastructure; ChatGPT used to summarize TTPs
04
Containment & Response
IP blocks deployed, WAF rules updated, PagerDuty incident escalated
05
Post-Incident Report
LLM-generated draft reviewed and submitted within 40 minutes of resolution
STEP 01: DETECTION
Coordinated DDoS + WAF Evasion Attack
At 02:14 AM, Cloudflare WAF flagged a 340% spike in requests targeting a client's login endpoint from 47 distinct ASNs, a classic distributed low-and-slow credential stuffing pattern designed to evade volume-based thresholds.
  • Attack vector: Credential stuffing via rotating residential proxies
  • Target: Enterprise e-commerce login page across 3 regions
  • Volume: ~18,000 requests/minute at peak
  • Evasion technique: Varied User-Agent strings and request timing
18K
Req/min at peak
47
Distinct ASNs
🔧 The Detection Rule That Came Out of This Incident

After this attack, the existing WAF rule was too broad and generated noisy false positives. Here's the actual before/after.

Before: 41% false positive rate After: 6% false positive rate
12rule: rate_limit(requests > 100, window=60s, scope=ip)
13action: block_ip(duration=300s)
12+rule: rate_limit(requests > 100, window=60s, scope=asn_cluster)
13+rule: behavioral_score(ua_entropy > 0.7, timing_variance < 200ms)
14+action: challenge(type=js_proof_of_work) // soft block before hard block
15+escalation: block_ip(duration=300s) // only after challenge failure
Why this mattered: the original rule blocked by single IP, which is useless against rotating residential proxies. The fix clusters by ASN behavior and adds a JS proof-of-work challenge as a soft gate before a hard IP block, legitimate users pass invisibly, automated clients get stuck on the challenge.
Intelligence Operations

Threat Intelligence Dashboard

A real-time simulation of the kind of threat intelligence environment I operate in daily, tracking IOCs, MITRE ATT&CK TTPs, and global attack vectors.

🔴 Critical Threats
0
Active CVEs being exploited in the wild
↑ 14% this week
🛡️ Alerts Resolved
~10K
Lifetime enterprise security alerts triaged
↓ 30% FP rate via ML tuning
⚡ Mean Time to Detect
18min
AI-augmented MTTD (down from 4 hours)
↓ 93% improvement
🗺️ MITRE ATT&CK Framework Coverage Tactics I actively monitor & respond to
Live IOC Feed
LIVE
Top Attack Vectors: 2025
Offensive Research

CTF & HackTheBox Achievements

Hands-on offensive security practice, sharpening red team skills to build a stronger blue team mindset.

8+
Machines Pwned
8
CTF Events Participated
Top 1%
TryHackMe Ranking
HoLmes
HTB CTF 2025 Cert
🟢
Hack The Box
Offensive Labs · CTF Competitions
HoLmes CTF 2025
Forensics · Web · OSINT
Certified ✓
Web Exploitation Labs
SQLi · XSS · SSRF · LFI
5 Solved
Forensics Track
Memory · Disk · Network PCAP
3 Solved
🧩 Web 🔬 Forensics 🕵️ OSINT
🔴
TryHackMe
Blue & Red Team Learning Paths
SOC Level 1 & 2
Alert Triage · SIEM · Threat Intel
Completed ✓
Jr Penetration Tester
Web · Network · Exploitation
Completed ✓
Advent of Cyber
Annual 25-day challenge
Top 1%
Global RankingTop 1%
🛡️ Blue Team ⚔️ Red Team ☁️ Cloud
Achievements

Trophy Wall

A scannable snapshot of the milestones that took years to earn, compressed into one wall.

🥇
9.47
CGPA: University Gold Medallist
🛡️
40+
Industry Certifications Earned
10K+
Security Alerts Triaged
🚩
8+
HackTheBox Machines Pwned
🏆
Top 1%
TryHackMe Global Ranking
🎯
18min
AI-Augmented Mean Time to Detect
📉
30%
False Positive Reduction via ML
🎓
HoLmes
HTB CTF 2025 Certificate
🃏 The SOC Trading Card

A single shareable card, built for LinkedIn, not a filing cabinet. Download it as an image.

★★★★★ LEGENDARY
SOC ENGINEER
AG
Aditya Kumar Goswami
Associate SOC Engineer · AI-Augmented Blue Team
DETECTION
FORENSICS
AI OPS
CLOUD SEC
Work With Me

Services & Engagements

Freelance security work, mentorship, and training, drawn directly from real SOC and offensive research experience.

Open to freelance, 3 project slots available this month
🛡️
VAPT Assessment
Web app, network & API penetration testing with a full remediation report mapped to OWASP Top 10.
  • Scoping call + recon
  • Manual + automated testing
  • Severity-ranked report (PDF)
  • 1 free re-test included
Custom Quote5–10 days
Request Quote →
☁️
Cloud Security Audit
AWS-focused review. IAM hygiene, S3 exposure, CloudTrail logging gaps, Security Hub configuration.
  • IAM & permissions review
  • Public exposure scan
  • Logging & monitoring gaps
  • Prioritized fix checklist
Custom Quote3–7 days
Request Quote →
🎓
1:1 Mentorship
Career guidance, certification prep (CEH, CompTIA, SOC roles), resume review, mock interviews.
  • 60-min focused session
  • Personalized study roadmap
  • Resume + LinkedIn audit
  • Follow-up notes via email
Custom Quoteper session
Book Session →
📝
Resume & LinkedIn Review
Cybersecurity-specific resume audit and LinkedIn profile optimization to actually pass ATS and recruiter scans.
  • Line-by-line resume feedback
  • Keyword/ATS optimization
  • LinkedIn headline + about rewrite
  • 48-hour turnaround
Custom Quote1–2 days
Get Started →
🚩
CTF Team Coaching
Coach college or corporate teams ahead of CTF competitions, web, forensics, and OSINT modules.
  • Skill-gap assessment
  • Practice room walkthroughs
  • Live competition support
  • Post-event debrief
Custom Quoteflexible
Inquire →
📡
SOC Retainer: Basic
Ongoing coverage for teams that need ears-on-glass without a full-time hire, lightweight tier.
  • Weekly threat intelligence briefing
  • Tailored to your specific stack
  • Email delivery, no dashboard needed
  • Cancel or upgrade anytime
Custom Quotemonthly
Request Quote →
📡
SOC Retainer: Standard
Wazuh/SIEM monitoring setup plus a monthly security posture report, mid-tier ongoing coverage.
  • SIEM monitoring setup & maintenance
  • Monthly security posture report
  • Includes everything in Basic tier
  • Priority response on findings
Custom Quotemonthly
Request Quote →
📡
SOC Retainer: Premium
Full SOC consulting with an incident response SLA and quarterly audits, top-tier ongoing coverage.
  • Full SOC consulting engagement
  • Incident response SLA included
  • Quarterly security audits
  • Includes everything in Standard tier
Custom Quotemonthly
Request Quote →
Want something to share internally?
Generate a tailored one-page proposal for any service, ready to print or save as PDF.
Prefer to just talk it through?
Book a free 15-minute discovery call, no form, no waiting for email replies.
Start a Project

Tell me a bit about what you need. I'll respond within 24 hours with a scoped quote.

Certifications

40+ Industry Certifications

Every certification listed below is verifiable. Click the 🔗 verify link on any card to confirm authenticity on the issuer's platform.

Blue Team Junior Analyst
Security Blue Team
🔗 VerifySOC
SOC Level 1
TryHackMe
🔗 VerifySOC
SOC Level 2
TryHackMe
🔗 VerifySOC
HoLmes CTF 2025
Hack The Box
🔗 VerifySOC
Multi-Cloud Blue Team Analyst
CyberWarFare Labs
🔗 VerifySOC
Cyber Security Analyst
CyberWarFare Labs
🔗 VerifySOC
Cyber Threat Management
Cisco Networking Academy
🔗 VerifySOC
Introduction to Cybersecurity
Cisco / TryHackMe
🔗 VerifySOC
Multi-Cloud Red Team Analyst
CyberWarFare Labs
🔗 VerifyVAPT
Vulnerability Management Detection & Response
Qualys
🔗 VerifyVAPT
Cisco Certified Ethical Hacker
Cisco
🔗 VerifyVAPT
Certified Ethical Hacker (CEH)
PrepInsta
🔗 VerifyVAPT
Android Bug Bounty Hunting
EC-Council
🔗 VerifyVAPT
Ethical Hacking Essentials (EHE)
EC-Council
🔗 VerifyVAPT
OS Forensics V10 Triage
PassMark Software
🔗 VerifyDFIR
Belkasoft iOS Forensic
Belkasoft
🔗 VerifyDFIR
Open Source Intelligence (OSINT)
Basel Institute on Governance
🔗 VerifyDFIR
Digital Forensic Essentials (DFE)
EC-Council
🔗 VerifyDFIR
Network Defense Essentials (NDE)
EC-Council
🔗 VerifyDFIR
Dark Web Forensics Workshop
Tinkering Hub, Parul Univ.
🔗 VerifyDFIR
ISO 27001:2022 Lead Auditor
Mastermind
🔗 VerifyGRC
ISO 27001:2022 Internal Auditor
Quality Asia Certifications
🔗 VerifyGRC
(ISC)² Certified Cybersecurity
ISC2
🔗 VerifyGRC
SC-900 Microsoft Security Compliance
Udemy
🔗 VerifyGRC
CISSP Foundation
Charles Sturt University
🔗 VerifyGRC
Advanced Cyber Security Governance
Great Learning
🔗 VerifyGRC
AWS Cloud Practitioner Essentials
Amazon Web Services
🔗 VerifyCloud
AWS Security Fundamentals
Amazon Web Services
🔗 VerifyCloud
Open Source○ Loading...

GitHub Activity

Contribution Activitygithub.com/Aditya-Sec →
JanFebMarAprMayJunJulAugSepOctNovDec
Less
More
6
Public Repositories
🔀
12
Total Stars Earned
🐍
Python
Primary Language
🛡️
Blue Team
Primary Focus
ReconVeritas-Automated-Recon-Tool
Advanced OSINT & recon automation framework
Python
⭐ 4🔀 2
Kibana-SIEM-Dashboard-Demo
Brute force detection with custom ML rules
Shell
⭐ 3
RedTeam-WAF-Detection-Bypass-Lab
WAF bypass techniques and mitigation research
Python
⭐ 5
📡 Portfolio Status
All Systems Operational
Site Availability 99.9%
Page Load Time measuring...
GitHub API checking...
Last Deployment June 2026
SSL / Security Headers ✓ Enforced
Insights & Research

Published Articles & Research

Original research, case studies, and practical guides from the frontlines of enterprise security operations. Follow on LinkedIn for new posts, with a dedicated Medium publication launching soon for longer-form technical deep-dives.

📰 Launching on Medium Soon
Longer-form technical breakdowns, incident retrospectives, and AI-in-cybersecurity deep-dives that don't fit a LinkedIn post. Follow on LinkedIn now to get notified at launch.
Get Notified →
SOC Operations Jan 2025 · 8 min read
Zero Trust Architecture in Modern SOC Operations
+

Zero Trust shifts security from the traditional perimeter-based model to an identity-centric "never trust, always verify" framework. After implementing Zero Trust principles at Investis Digital, here's what the data showed after 90 days:

  • Micro-segmentation limited lateral movement. APT dwell time dropped 68%
  • MFA + behavioral analytics reduced credential-based attacks by 73%
  • Wazuh ML rules brought MTTD from 4 hours down to 18 minutes
  • 60% fewer false positives, 85% faster incident containment
Read full article on LinkedIn →
Threat Hunting Nov 2024 · 12 min read
The Art of Proactive Threat Hunting: From Reactive SOC to AI-Augmented Hunter
+

Most SOC teams are purely reactive, they wait for alerts. This piece documents my transition to proactive threat hunting using AI-generated hypotheses and ML-driven anomaly baselining. Two real discoveries from production environments:

  • DGA pattern in DNS queries surfaced a malicious npm package, no alert had triggered
  • Exposed S3 bucket with customer PII found via automated OSINT sweep before any breach
  • LLM-generated threat intel summaries powering hypothesis-driven hunting frameworks
  • ML baselines normal behaviour, anomalies surface within minutes of deviation
Read full article on LinkedIn →
Cloud Security Sep 2024 · 10 min read
Cloud Security Blind Spots: 5 AWS Misconfigurations That Led to Real Breaches
+

After analyzing 200+ cloud security incidents, the pattern is consistent: most breaches aren't zero-days, they're misconfigurations that existed for months. Here are the five I see repeatedly in the wild, and exactly how to prevent each:

  • 1. IAM Permission Sprawl: an 18-month-old API key caused a full data exfiltration
  • 2. CloudTrail disabled silently, attacker turned off logging before launching crypto-miner
  • 3. Public S3 exposure. Block Public Access + automated Prowler scanning prevents 90%
  • 4. Security group 0.0.0.0/0, replaced SSH with Systems Manager entirely
  • 5. AI automation (Lambda + Config + Security Hub) catches misconfigs within 4 minutes
Read full article on LinkedIn →
AI & Security Apr 2025 · 9 min read
What Actually Changes When You Put an LLM Inside a SOC Workflow
+

There's a lot of hype and very little specificity about AI in security operations. This piece breaks down exactly where LLMs help, where they don't, and what changed measurably after a year of using them daily:

  • Report drafting time dropped 70%, but every output still needs a human review pass
  • LLMs are excellent at summarizing known patterns, weak at flagging genuinely novel attacker behavior
  • The real win was agentic automation (n8n) chaining tool calls together, not chat-based Q&A
  • Verification discipline matters more with AI in the loop, not less
Read full article on LinkedIn →
GRC Feb 2025 · 7 min read
ISO 27001:2022 in Practice: What the Audit Doesn't Tell You
+

Passing an ISO 27001 audit and actually running a secure organization are two different things. After supporting a full audit cycle, here's where the framework's checklist nature creates blind spots:

  • Documented controls and operationally enforced controls are not the same thing
  • RCA documentation quality predicted audit friction better than control maturity did
  • Mapping NIST and CIS alongside ISO closed gaps the ISO checklist alone missed
  • The teams that treated GRC as a living process, not an annual event, audited the smoothest
Read full article on LinkedIn →
AI & Automation Coming to Medium · in progress
Building an Agentic SOC: What n8n Automation Actually Looks Like in Production
+

My first long-form Medium piece, currently in progress: a real walkthrough of the n8n agent pipelines I run for alert enrichment and triage, including the parts that didn't work the first time and what I changed.

  • Why a fully autonomous agent was the wrong starting point, and what I built instead
  • The exact LLM prompt structure that kept severity scoring consistent across runs
  • Where human review still has to stay in the loop, and why that's a feature, not a gap
Follow on LinkedIn for the launch →
Forensics HoLmes CTF 2025 · HackTheBox
Reconstructing a Timeline from a Corrupted NTFS Image
+

This challenge provided a partially corrupted disk image and asked for the exact sequence of attacker actions. The MFT was damaged in several sectors, which ruled out a straightforward timeline tool run.

  • 1. Carved $LogFile entries manually to recover transaction records the MFT had lost
  • 2. Cross-referenced USN Journal entries to fill in gaps around the corrupted timestamps
  • 3. Identified a renamed PowerShell binary used to evade basic filename-based detection
  • 4. Flag recovered by correlating shellbag artifacts with the reconstructed access pattern
MFTECmdNTFS ForensicsAutopsy
Web Exploitation HackTheBox · Medium Difficulty
Chaining an IDOR with a JWT Algorithm Confusion Bug
+

A REST API exposed user records via sequential numeric IDs (classic IDOR), but read-only data wasn't enough for full compromise, privilege escalation needed a second bug.

  • 1. Enumerated user IDs via the IDOR to harvest a victim's public key reference
  • 2. Server accepted both RS256 and HS256, switched algorithm and signed with the public key as an HMAC secret
  • 3. Forged an admin-scoped JWT, bypassing signature verification entirely
  • 4. Root cause: library accepted the "alg" header from the client instead of enforcing server-side config
Burp SuiteJWT.ioPython
OSINT HoLmes CTF 2025 · Hard Difficulty
Tracking a Threat Actor Through Reused Infrastructure Metadata
+

Given only a single malicious domain, the challenge asked for the actor's other active infrastructure, a real-world attribution exercise rather than a typical flag hunt.

  • 1. Pivoted from the seed domain's SSL certificate fingerprint to find 6 related domains
  • 2. Passive DNS history revealed a shared hosting IP reused across all identified domains
  • 3. Favicon hash matched a known phishing kit, confirming the campaign's tooling
  • 4. Flag was the registrant email exposed in an early, unprotected WHOIS snapshot
crt.shShodanVirusTotal
Free Resources

Resources & Extras

A weekly briefing and a couple of interactive ways to test yourself, built for anyone curious about cybersecurity, not just recruiters.

💡 Security Tip of the Day
🛡️
Loading today's tip...
📬
Weekly Threat Briefing
5 bullet points every week, the CVEs that mattered, one tool worth knowing, and one thing I learned in the SOC. No spam, unsubscribe anytime.
🎯 Can You Spot the Phishing Email?
Question 1 of 5
Growth Mindset

Roadmap & Future Direction

M.S. Cybersecurity is complete. Here are the six directions I'm actively evaluating and building toward next, each with real progress already underway.

✓ COMPLETED
🎓
M.S. Cybersecurity
Completed 2024 to 2026 alongside full-time SOC work. Capstone project: CyberShield AI, an AI-based phishing URL detection and malware scanner with LLM-generated threat reports.
Degree Progress100%
PostgraduateAI Capstone
● ACTIVE
🤖
AI Security / AI-Augmented Defense
Prompt injection defense, LLM security, AI-driven SOC automation, and adversarial ML. The direction I'm most actively building toward right now, given how much of my daily work already runs through AI tooling.
Progress40%
AI SecurityAgentic Workflows
● ACTIVE
🎯
Offensive Security / Red Team
OSCP path, advanced VAPT methodology, and red team operations. Sharpening offensive skills directly strengthens how I think about defense.
Study Progress35%
OSCPRed Team
NEXT
☁️
Cloud Security Architecture
Multi-cloud security across AWS, Azure, and GCP, Zero Trust design, container and Kubernetes security, and cloud-native SIEM at an architect level.
Progress20%
AWSZero Trust
NEXT
🔍
DFIR Specialist
Advanced digital forensics certifications, malware reverse engineering, and deeper incident response specialization beyond current SOC-level DFIR work.
Progress15%
ForensicsMalware RE
PLANNED
📋
GRC & Compliance Leadership
ISO 27001 Lead Implementer, broader risk management frameworks, audit leadership, and a path toward virtual CISO advisory work.
Progress10%
ISO 27001vCISO
PLANNED
👔
Security Leadership / CISO Track
Security program management, board-level reporting, team leadership, and budget ownership, the long-term direction once the technical foundation across the other tracks is solid.
Progress5%
Leadership2027+ Goal
Social Proof

What Colleagues Say

Endorsements from managers and peers, the human side of the résumé.

"
★★★★★
Aditya consistently goes beyond alert triage. His ability to correlate weak signals across multiple data sources, and communicate findings clearly to non-technical stakeholders, is rare at his experience level. He's the kind of analyst every SOC team needs.
SM
Senior Manager, SOC
Investis Digital Pvt Ltd
"
★★★★★
What sets Aditya apart is how he applies AI tools practically in SOC workflows. He built automation scripts that saved our team hours weekly and wrote detection rules that reduced our false positive rate significantly. A proactive, self-driven professional.
TL
Team Lead, Security Engineering
Investis Digital Pvt Ltd
"
★★★★★
During his internship, Aditya demonstrated exceptional understanding of forensic analysis workflows. His CGPA and Gold Medal reflect genuine aptitude, he combines academic rigor with hands-on practicality, which is uncommon in early-career professionals.
PS
Forensics Supervisor
Regional Forensic Science Lab
"
★★★★★
I've worked shoulder to shoulder with Aditya on live incidents, and what stands out is how calm he stays under pressure. He doesn't just close tickets, he actually understands the why behind an attack chain before writing it up. That's a rarer skill than people think.
SE
SOC Engineer, Colleague
Investis Digital Pvt Ltd
"
★★★★★
Aditya is one of the few people on our team who actually documents things well enough that someone else could pick up his work mid-incident without missing context. That habit alone has saved us real time during shift handovers.
SO
Security Operations Specialist
Investis Digital Pvt Ltd
"
★★★★★
What impressed me about Aditya during our engagement was how quickly he picked up context on a client's environment and started flagging real risk, not just textbook findings. He brings genuine curiosity to offensive work, which is exactly what good VAPT needs.
CO
Co-Founder
Cyber Octet Private Limited
"
★★★★★
Aditya has the rare combination of technical depth and genuine willingness to mentor others coming up in the field. The certifications are impressive on paper, but what actually matters is that he can explain complex security concepts simply, that's a leadership trait, not just a technical one.
FO
Founder
Sannibh Technologies
📍 Where Visitors Are Coming From

Real, anonymized traffic sources, refreshed each time this page loads. No fabricated logos, just honest numbers.

Direct
Your Source
Detecting...
Device Type
Counting...
Your Visit #
Contact

Let's Connect

Looking to hire, collaborate, or discuss cybersecurity and AI? I'd love to hear from you.

Send a Message
📞
PHONE
+91 97262 79007
📍
LOCATION
Vadodara, Gujarat, India
🔗
CONNECT