Skip to content
View RUTHRAN-SEC's full-sized avatar
โ™พ๏ธ
โ™พ๏ธ

Block or report RUTHRAN-SEC

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
RUTHRAN-SEC/README.md
Profile Views Typing SVG

๐Ÿ‘พ About Me

#!/usr/bin/env python3
# ruthran_profile.py

class SOCAnalyst:
    def __init__(self):
        self.name            = "Ruthran"
        self.alias           = "RUTHRAN-SEC"
        self.location        = "India ๐Ÿ‡ฎ๐Ÿ‡ณ"
        self.role            = "Aspiring SOC Analyst | Blue Teamer"
        self.degree          = "B.Voc Data Science @ The American College (2024โ€“2027)"
        self.email           = "ruthran.sec@gmail.com"

        self.stack = [
            "Splunk (SPL ยท Dashboards ยท Alerts)",
            "Elastic Stack", "Wireshark", "Sysmon",
            "Microsoft Defender", "CrowdStrike (Concept)",
            "Cisco ASA Firewall", "Cisco Packet Tracer",
            "VirusTotal ยท AbuseIPDB ยท Any.Run",
            "MITRE ATT&CK ยท Cyber Kill Chain",
        ]

        self.currently_learning = [
            "๐Ÿ”ด Malware Reverse Engineering โ†’ Static & Dynamic Analysis",
            "โ˜๏ธ  Cloud Security โ†’ AWS ยท Azure Sentinel",
            "๐Ÿ Python Scripting โ†’ Log Parsing ยท SOAR Automation",
            "๐Ÿ“œ Sigma Rules โ†’ Custom Detection Engineering",
        ]

        self.fun_fact  = "I map every suspicious event to MITRE ATT&CK before breakfast โ˜•"

    def motto(self) -> str:
        return "Detect. Investigate. Respond. Repeat."

me = SOCAnalyst()
print(me.motto())


๐Ÿ›ก๏ธ Tech Stack & Tools

๐Ÿ–ฅ๏ธ SIEM & Log Analysis

Splunk Elastic Stack Windows Event Logs Sysmon Linux Logs

๐ŸŒ Network Security & Analysis

Wireshark Tcpdump Cisco ASA Cisco Packet Tracer Wireshark

๐Ÿ” Threat Intelligence & OSINT

VirusTotal AbuseIPDB AlienVault OTX MITRE ATT&CK Any.Run urlscan.io

๐Ÿ–ฑ๏ธ EDR / Endpoint

Microsoft Defender CrowdStrike SentinelOne Sysinternals

๐Ÿ”ง Tools & Frameworks

CyberChef Autopsy Sigma Rules Python Hybrid Analysis


๐Ÿ”ฅ Streak Stats


๐Ÿ“ˆ Activity Graph


๐Ÿ’ผ Work Experience & Learning Journey

๐Ÿ›ก๏ธ SOC Analyst Self-Study Roadmap ย |ย  Phases 1โ€“10 ย |ย  2024 โ€“ 2026 ย |ย  Remote

Networking Windows OS Sysmon Linux Splunk SIEM Log Analysis SOC Investigations Threat Detection MITRE ATT&CK EDR/XDR

  • Completed a structured 10-phase SOC Analyst roadmap covering all core blue team disciplines from network fundamentals through advanced EDR/XDR operations.
  • Mastered Splunk SPL query writing โ€” built dashboards, alerts, and reports for real-world investigation scenarios including brute force, phishing, and malware triage.
  • Developed deep expertise in Windows Event Log analysis (EIDs 4624/4625/4688/4720) and Sysmon correlation (EIDs 1/3/7/8/10/11/13/22) for endpoint threat hunting.
  • Mapped every investigation finding to MITRE ATT&CK techniques, applying Cyber Kill Chain and Diamond Model frameworks for structured adversary behavior analysis.
๐Ÿ“œ Google Cybersecurity Professional Certificate ย |ย  Google / Coursera ย |ย  2024

Security Fundamentals Network Security Linux Python SIEM Incident Response SQL

  • Completed all 8 courses covering threat analysis, vulnerability assessment, network hardening, and incident response lifecycle.
  • Applied hands-on labs in Python scripting for security automation and SQL for log querying.
  • Studied NIST CSF, security frameworks, and risk management principles applicable to real SOC environments.
  • Earned certification validating foundational cybersecurity skills aligned with industry SOC Tier 1 role requirements.
๐ŸŒ Cisco Endpoint Security Certification ย |ย  Cisco Networking Academy ย |ย  2024

Endpoint Security Cisco Technologies Malware Defense Network Access Control AAA

  • Studied endpoint protection strategies including antivirus/EDR deployment, host-based intrusion detection, and device compliance.
  • Covered AAA (Authentication, Authorization, Accounting) and network access control architectures used in enterprise environments.
  • Gained knowledge of Cisco security product ecosystem relevant to real-world SOC toolsets and vendor environments.

๐Ÿš€ Featured Projects

Project Stack Highlights
๐Ÿ”ต SOC Hands-On Investigations & DFIR Portfolio Splunk Elastic Wireshark Any.Run VirusTotal MITRE ATT&CK 176+ commits of real-world SOC investigations ยท Covers phishing, malware, brute force, crypto hijacking, NTA & CVE analysis ยท Full IOC extraction, enrichment & incident documentation
๐Ÿ›๏ธ Enterprise Network Architecture 2026 Cisco Packet Tracer ASA Firewall VLANs ACLs SIEM Syslog TACACS+ 10 VLANs (HR/Finance/IT/SOC/DMZ) with Zero Trust inter-VLAN ACL policies ยท ASA firewall with 3 security zones, static NAT, PAT, extended ACLs ยท Full Layer 2 attack mitigations: DHCP Snooping, DAI, Port Security, BPDU Guard

๐Ÿ… Achievements & Certifications

๐Ÿ† Achievement Details
๐ŸŽ“ Google Cybersecurity Professional Certificate All 8 courses โ€” Security, Linux, Python, SIEM, IR
๐ŸŒ Cisco Endpoint Security Cisco Networking Academy certified
๐Ÿ“‚ SOC Portfolio โ€” 176+ Commits Comprehensive DFIR & SOC investigation portfolio on GitHub
๐Ÿ—บ๏ธ MITRE ATT&CK Practitioner All investigations mapped to ATT&CK techniques
๐Ÿ›ก๏ธ SOC Roadmap โ€” Phases 1โ€“10 Complete Self-study covering full blue team operations lifecycle
๐Ÿ—๏ธ Enterprise Network Architect Designed banking/healthcare-grade network simulation from scratch
๐Ÿ” Multi-Platform SIEM Proficiency Splunk SPL + Elastic Stack investigations
๐Ÿ•ต๏ธ Threat Intelligence Analyst VirusTotal ยท AbuseIPDB ยท AlienVault OTX ยท urlscan.io ยท Any.Run
๐Ÿ Python Scripting for Security JSON ยท CSV ยท Regex ยท Requests ยท Log Parsing
๐Ÿ“‹ Incident Documentation Specialist Structured IR reports with IOC extraction & remediation notes

๐ŸŽ“ Education

Degree Institution Year Status
B.Voc Data Science The American College 2024 โ€“ 2027 ๐ŸŸข In Progress

๐Ÿ“š Currently Learning

๐Ÿ”ด  Malware Reverse Engineering  โ†’  PE Analysis ยท Static Strings ยท Dynamic Sandboxing
โ˜๏ธ   Cloud Security              โ†’  AWS Security Hub ยท Microsoft Azure Sentinel ยท CloudTrail
๐Ÿ  Python for Security          โ†’  SOAR Automation ยท Log Parsing ยท API Integration
๐Ÿ“œ  Detection Engineering        โ†’  Custom Sigma Rules ยท Alert Tuning ยท False Positive Reduction
๐Ÿง   Threat Hunting               โ†’  Hypothesis-Driven Hunting ยท Living-Off-The-Land TTPs
๐Ÿ•ต๏ธ   DFIR Deep Dive              โ†’  Memory Forensics (Volatility) ยท Disk Forensics (Autopsy)

๐Ÿค Connect With Me

LinkedIn GitHub Email


"In a world of noise, the SOC analyst finds the signal."

Detect. Investigate. Respond. Repeat. ๐Ÿ›ก๏ธ

Pinned Loading

  1. SOC-Hands-on-Investigation-and-Challenges SOC-Hands-on-Investigation-and-Challenges Public

    SOC / DFIR investigations portfolio with hands-on lab cases covering SIEM alert triage, Phishing Analysis, Malware analysis, Endpoint detection, Network Analysis. Built to demonstrate practical SOCโ€ฆ

    1