Cybersecurity graduate based in Limerick, Ireland, focused on SOC operations, detection engineering, SIEM pipelines, threat intelligence integration, and network security monitoring.
I build hands-on security labs that simulate enterprise environments, generate security telemetry, forward logs into SIEM platforms, and document detections in a portfolio-ready format.
- SOC monitoring and detection engineering
- SIEM log collection, parsing, and alerting
- Network intrusion detection with Zeek and Suricata
- Windows and Active Directory security monitoring
- Cyber threat intelligence pipelines
- Python-based security tooling
- Cryptography and secure protocol design
| Project | What it Demonstrates | Tools / Technologies |
|---|---|---|
| Enterprise Detection Lab | Home SOC lab with firewall, AD, endpoint telemetry, network IDS, Splunk log forwarding, and detection use cases | pfSense, Splunk, Zeek, Suricata, Active Directory, Windows, Sysmon |
| CTI Integration Pipeline | End-to-end cyber threat intelligence pipeline using OpenCTI, AlienVault OTX, and Splunk | OpenCTI, AlienVault OTX, Splunk, Docker Compose, Elasticsearch, Redis, RabbitMQ |
| ThreatScope | Real-time and offline network intrusion detection using packet capture, flow features, and ML classification | Python, Scapy, PyShark, XGBoost, Random Forest, FastAPI, SQLite, Docker |
| Three-Party Key Establishment Protocol | Secure session key establishment between three entities with certificates, signatures, and encrypted chat | Python, RSA, AES-GCM, Certificates, Pytest, GitHub Actions |
- Built a mini-enterprise network with pfSense, Active Directory, Windows endpoint, Splunk, Zeek, Suricata, and attacker VM.
- Centralised firewall, Windows, AD, Zeek, and Suricata logs into Splunk.
- Created detection use cases for failed logons, suspicious PowerShell activity, Suricata alerts, and suspicious DNS traffic.
- Documented architecture, setup steps, configs, detections, and findings.
- Deployed OpenCTI using Docker Compose on Ubuntu.
- Integrated AlienVault OTX as an external threat intelligence source.
- Connected CTI data into Splunk for downstream visibility.
- Documented deployment, connector setup, troubleshooting, and validation steps.
- Built a Python-based intrusion detection tool for live and offline traffic analysis.
- Extracted flow-level features from packets and PCAP files.
- Used ML models such as XGBoost and Random Forest for classification.
- Exposed predictions and alerts through a FastAPI service.
I am seeking entry-level cybersecurity roles in:
- SOC Analyst
- Security Analyst
- Detection Engineer
- Cybersecurity Analyst
- Threat Intelligence Analyst
- Security Operations Engineer
My strongest areas are SIEM workflows, detection logic, log analysis, network monitoring, and hands-on lab-based investigation.
- LinkedIn: Sushank Yerva
- GitHub: SushankYerva