任务控制 |
从这里开始 |
防御实验室 |
我的防御之道 |
安全武器库 |
职业履历
## 任务控制
我构建蓝队系统,将安全遥测数据转化为清晰的检测、丰富的证据和可重复的响应路径。我最擅长的领域是涵盖云、身份、端点、电子邮件、DLP、SIEM和自动化工作流的检测工程。
```
Primary lane Detection engineering, SIEM tuning, cloud defense, alert validation
Operating style Risk story -> telemetry check -> detection logic -> enrichment -> runbook
Core tooling Splunk SPL, Datadog monitor-as-code, AWS, Python, CrowdStrike, Defender, Prisma/Cortex
Outcome Faster analyst decisions backed by clean evidence
```
## 从这里开始
| 最佳首选点击 | 为什么重要 |
| --- | --- |
| [云检测工程平台](https://github.com/Kalla-Bhanu/Cloud-Detection-Engineering-Platform) | 顶点云检测实验室,连接合成 AWS 事件、detections-as-code、预期警报、验证、runbook、仪表盘 artifacts 和公共安全证据。 |
| [Datadog 检测工程实验室](https://github.com/Kalla-Bhanu/Datadog-Detection-Engineering-Lab) | Detection-as-code 原则:监控逻辑、验证测试工具、负向控制、CI 检查、ATT&CK 映射和 runbook。 |
| [CloudSec 检测实验室](https://github.com/Kalla-Bhanu/CloudSec-SOC-Detection-Lab) | 优先针对 AWS 的云防御,涵盖 CloudTrail、IAM、STS、S3、EKS、KMS、Lambda 重放和证据模板。 |
## 防御实验室
| 实验室 | 它证明了什么 |
| --- | --- |
| [云检测工程平台](https://github.com/Kalla-Bhanu/Cloud-Detection-Engineering-Platform) | 公共安全的云检测工程,涵盖合成 AWS 事件、detections-as-code、预期警报、验证、runbook、仪表盘 artifacts 和 CI 检查。 |
| [Datadog 检测工程实验室](https://github.com/Kalla-Bhanu/Datadog-Detection-Engineering-Lab) | Monitor-as-code、验证、调优、CI 验证、ATT&CK 映射和分诊 runbook。 |
| [CloudSec 检测实验室](https://github.com/Kalla-Bhanu/CloudSec-SOC-Detection-Lab) | 通过 AWS 遥测重放、身份/云上下文以及分析师可直接使用的证据进行云检测工程。 |
| [SaaS 攻击链检测实验室](https://github.com/Kalla-Bhanu/SaaS-Attack-Chain-Detection-Lab) | 使用 Okta、Google Workspace、Atlas 活动记录、Sigma 风格规则和公共安全 artifacts 进行 SaaS 威胁建模。 |
| [security-ml-threat-detection](https://github.com/Kalla-Bhanu/security-ml-threat-detection) | 安全分析、异常检测、特征工程和高风险行为建模。 |
| [soc-monitoring-credit-approval](https://github.com/Kalla-Bhanu/soc-monitoring-credit-approval) | 针对敏感财务和 PII 流程的事件工作流监控。 |
| [SMART-ATS](https://github.com/Kalla-Bhanu/SMART-ATS) | 产品工程,涵盖文档解析、工作流自动化和实用的 AI 辅助用户体验。 |
## 我的防御之道
| 阶段 | 我关注的重点 |
| --- | --- |
| 建模风险 | 哪些行为重要,哪些资产暴露在外,以及什么后果会造成损害。 |
| 验证遥测数据 | 来源时效性、schema 质量、身份关联、缺失的上下文以及误报压力。 |
| 构建检测 | 可解释的逻辑,与行为相映射,并通过正向和负向用例进行测试。 |
| 封装响应 | 证据路径、分诊问题、升级说明和调优历史。 |
## 安全武器库
| 检测 & SIEM | 云 & CNAPP | 身份、端点 & 电子邮件 | 自动化 & 响应 |
| --- | --- | --- | --- |
| Splunk SPL | AWS CloudTrail | Entra ID / Azure AD | Python |
| Datadog monitor-as-code | GuardDuty / Security Hub | Duo / Okta 概念 | Bash / PowerShell |
| Sigma 风格规则 | IAM / STS / KMS / S3 | CrowdStrike Falcon | ServiceNow / Jira |
| ATT&CK 映射 | Prisma / Cortex Cloud | Microsoft Defender / O365 | Runbooks / RCA |
| 误报调优 | 漏洞上下文 | Proofpoint 概念 | GitHub Actions |
## 职业履历
| 角色 | 履历 |
| --- | --- |
| 安全工程师,American Express | 跨越身份、电子邮件、端点、云、DLP 和漏洞风险领域的检测生命周期工作。 |
| 安全分析师,Northeastern University | 端点、身份、网络钓鱼、访问审查、防火墙、SIEM 和 ServiceNow 调查工作流。 |
| 安全分析师实习生,FILESIE | SIEM 警报分析、符合 ATT&CK/OWASP 标准的调优、攻击路径建模、控制验证和 Python 仪表盘。 |
| 教育背景 | 时间线 |
| --- | --- |
| Northeastern University,信息安全管理专业研究硕士 | 2023 - 2025 |
| GITAM University,Visakhapatnam,计算机科学与工程 B.Tech | 2019 - 2023 |
## 正在构建
```
roadmap.status = "active"
current.signal = "Cloud Detection Engineering Platform"
next.quality = "richer synthetic telemetry, validation harnesses, negative controls, and tuning history"
next.story = "cleaner incident narratives that connect alerts to analyst decisions"
```