Security engineer. I reverse-engineer how adversaries behave, turn that behavior into detections, and build the AI agents that run those detections at scale.
My work lives at the seam where detection engineering, threat intelligence, and agentic security operations meet — a SOC that runs itself instead of drowning its analysts.
$ cat /etc/indranil.conf
focus detection engineering · agentic SOC · threat intel
day-job SOC ops · incident response · purple teaming · cloud & fraud defense
shipping agents that triage, hunt, and respond — no human in the loop
writing adversary tradecraft & detection research @ vo1dlabs.comAgentic SOC — multi-agent systems that triage alerts, run hunts, and drive response end to end. Built to cut analyst noise, not manufacture more of it.
Detection engineering — rules mapped to MITRE ATT&CK and tuned for signal, not volume. Coverage up, false positives down, alert fatigue gone.
Threat intelligence — pipelines that turn raw indicators into live detections, with MISP wired into the tools analysts and agents actually reach for.
Open-source tooling — most of what I build ships publicly: MCP servers that feed threat intel to AI agents, security scanners for agentic repos, Slack-native SOC agents, training labs, and detection-translation engines. Pinned below.
detection MITRE ATT&CK · Sigma · S1QL / KQL · SentinelOne · Wazuh · Suricata · Snort
threat intel MISP · FS-ISAC · IOC pipelines · enrichment
platforms SIEM · EDR / XDR · SOAR · AWS security
building Python · TypeScript · Node · MCP · multi-agent AI
offense purple teaming · adversary emulation · malware & red-team tradecraft
| writing | indranilroy9.medium.com — detection engineering, threat hunting, adversary behavior |
| lab | vo1dlabs.com |
| in/vo1d |
Turn red-team tactics into proactive hunting. Turn hunting into detections. Turn detections into agents that never sleep.