Skip to content
View indranilroy99's full-sized avatar

Block or report indranilroy99

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
indranilroy99/README.md

whoami

Security engineer. I reverse-engineer how adversaries behave, turn that behavior into detections, and build the AI agents that run those detections at scale.

My work lives at the seam where detection engineering, threat intelligence, and agentic security operations meet — a SOC that runs itself instead of drowning its analysts.

$ cat /etc/indranil.conf

focus     detection engineering · agentic SOC · threat intel
day-job   SOC ops · incident response · purple teaming · cloud & fraud defense
shipping  agents that triage, hunt, and respond — no human in the loop
writing   adversary tradecraft & detection research @ vo1dlabs.com

what I build

Agentic SOC — multi-agent systems that triage alerts, run hunts, and drive response end to end. Built to cut analyst noise, not manufacture more of it.

Detection engineering — rules mapped to MITRE ATT&CK and tuned for signal, not volume. Coverage up, false positives down, alert fatigue gone.

Threat intelligence — pipelines that turn raw indicators into live detections, with MISP wired into the tools analysts and agents actually reach for.

Open-source tooling — most of what I build ships publicly: MCP servers that feed threat intel to AI agents, security scanners for agentic repos, Slack-native SOC agents, training labs, and detection-translation engines. Pinned below.


stack

detection    MITRE ATT&CK · Sigma · S1QL / KQL · SentinelOne · Wazuh · Suricata · Snort
threat intel MISP · FS-ISAC · IOC pipelines · enrichment
platforms    SIEM · EDR / XDR · SOAR · AWS security
building     Python · TypeScript · Node · MCP · multi-agent AI
offense      purple teaming · adversary emulation · malware & red-team tradecraft

elsewhere

writing indranilroy9.medium.com — detection engineering, threat hunting, adversary behavior
lab vo1dlabs.com
linkedin in/vo1d

Turn red-team tactics into proactive hunting. Turn hunting into detections. Turn detections into agents that never sleep.

Pinned Loading

  1. agentcsp agentcsp Public

    Open-source control plane for discovering, testing, and enforcing context security policy across AI agents, tools, MCP servers, RAG, memory, and runtime actions.

    TypeScript

  2. EvilCorp-Vulnerable-Web-App EvilCorp-Vulnerable-Web-App Public

    Intentionally vulnerable real estate web app for security training and labs

    JavaScript

  3. karpathy-skills karpathy-skills Public

    Forked from multica-ai/andrej-karpathy-skills

    A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.

  4. misp-mcp misp-mcp Public

    MCP server exposing MISP threat intelligence as tools for any MCP client. Per-user auth, write guardrails, stdio + hosted HTTP.

    Python

  5. myfilekit myfilekit Public

    MyFileKit is an all-in-one file and business tools workspace for creating invoices, editing PDFs, compressing images, signing documents, and managing everyday document workflows.

    TypeScript