Skip to content
View sahilsinghi's full-sized avatar

Block or report sahilsinghi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sahilsinghi/README.md

Hey, I'm Sahil 👋

Security analyst and DFIR practitioner based in Chennai. I investigate real incidents for a living — malware, account takeovers, financial intrusions — and I build tools on the side to close gaps I keep running into at work.

Previously at Alibi Technologies, where I was deployed to the Office of the Commissioner of Police, Chennai working on live cybercrime cases across CCB, FIW, and ATS. Currently looking for my next role in SOC, DFIR, or threat intelligence.


Portfolio Projects

I built these to solve problems I actually hit in my day-to-day work. Not coursework.

Project What it does
SOC Detection Lab 32 MITRE ATT&CK detection rules validated end-to-end on Splunk + Wazuh. Tuned out real FPs — including svchost→lsass 0x1000 status-query noise that fires on every Windows box.
SOAR Alert Triage n8n pipeline that auto-triages phishing emails and IP/URL alerts across 5 threat intel APIs with composite risk scoring and MITRE mapping.
APT Threat Actor Profiler Profiles APT groups from MITRE STIX data — motivations, TTPs, targets, historical campaigns. Built to speed up threat intel writeups.
DPDP Compliance Tool Self-assessment tool for India's DPDP Act 2023. 66 questions, 11 obligation areas, client-side PDF report. Live →
ISO 27001 Tracker All 93 Annex A controls with maturity scoring, gap analysis, and a Stage-1 audit-readiness verdict. Live →

What I work with

IR & Forensics — Magnet AXIOM · Cellebrite · Autopsy · FTK · Volatility · chain of custody documentation

Detection & SIEM — Splunk · Wazuh · Sysmon · MITRE ATT&CK · Sigma · Cyber Kill Chain

Network Analysis — Wireshark · C2 infrastructure mapping · lateral movement reconstruction

VAPT — Burp Suite · Nessus · Nmap · Metasploit · OWASP Top 10

Scripting — Python · Bash


Where I've worked

🔹 Alibi Technologies LLP — Junior Security Analyst / DFIR Analyst (Nov 2025 – May 2026) Started as an intern at Alibi (Jul 2025). Work got noticed — Alibi deployed me to the Office of the Commissioner of Police, Chennai in Oct 2025, and the team there kept me on full-time from Nov 2025. Worked across CCB (Central Crime Branch), FIW (Financial Investigation Wing), and ATS (Anti-Terrorism Squad) on live cybercrime cases. Investigated 150+ incidents end-to-end (malware, account takeovers, financial intrusions), performed forensic acquisition on 100+ Windows/Linux/mobile endpoints using Magnet AXIOM, Cellebrite, Autopsy, FTK, and Volatility — 200+ IOCs fed into client SIEM blocklists.

🔹 IBM Phemesoft — Summer Intern (Jun – Jul 2024) Designed a Cloud Security Governance Toolkit aligned to NIST CSF and MITRE ATT&CK.


Certifications

  • CompTIA Security+ (SY0-701)
  • EC-Council CHFI Training / Workshops
  • VECTOR — Where Systems Collapse (Vulnshields & Cyber Secured India × MKITOS × OPSWAT Academy, May–Jun 2026) Practical sessions: recon, web exploitation, access control vulnerabilities, API security, LLM attacks

B.Tech. CSE (Cybersecurity & Forensics) — UPES Dehradun, 2025


📬 linkedin.com/in/sahilsinghi · sahilsinghi2002@gmail.com

Pinned Loading

  1. soc-detection-lab soc-detection-lab Public

    32 MITRE ATT&CK detection rules validated end-to-end — Splunk SIEM + Wazuh, Sysmon telemetry pipeline, Atomic Red Team validation

    PowerShell

  2. soar-alert-triage soar-alert-triage Public

    SOAR alert triage automation — n8n + 5 threat intel APIs, composite risk scoring, MITRE ATT&CK mapping. Auto-triages phishing and IP/URL alerts.

  3. dpdp-compliance-tool dpdp-compliance-tool Public

    India DPDP Act 2023 Compliance Self-Assessment Tool — 66 questions, 11 obligation areas, privacy-first, client-side PDF report

    TypeScript

  4. iso27001-compliance-tracker iso27001-compliance-tracker Public

    ISO 27001:2022 compliance tracker for all 93 Annex A controls

    TypeScript 1

  5. apt-threat-actor-profile apt-threat-actor-profile Public

    APT threat actor profiler — MITRE STIX data, motivation inference, TTP mapping, and historical campaign analysis

    TypeScript