Namaste 🙏🏼!
My name is Binod Rawat
I work as a
Specialized in SOC Operations, Threat Hunting, Detection Engineering, and Incident Response. I map adversary TTPs to the MITRE ATT&CK framework, craft custom Sigma & YARA rules, and build resilient defensive telemetry systems.
Featured Security Capabilities
Threat Hunting
Hypothesis-driven threat hunting targeting persistence, privilege escalation, and lateral movement.
Detection Engineering
Designing, testing, and tuning high-fidelity detection rules mapped to MITRE ATT&CK.
Incident Response
End-to-end incident handling, root-cause analysis, containment, and eradication playbooks.
MITRE ATT&CK Framework
Mapping adversary TTPs, gap analysis, and defense validation across enterprise matrix.
Wazuh SIEM
Architecting open-source XDR/SIEM, agent deployment, XML rule tuning, and decoder writing.
CrowdStrike Falcon
EDR telemetry monitoring, custom IOA creation, real-time response (RTR), and host isolation.
Industry Credentials
Falcon Administrator
CrowdStrike University • 2026-05
Incident Responder
CrowdStrike University • 2026-07
Threat Hunter
CrowdStrike University • 2026-06
Recent Technical Articles
Building Production-Grade Wazuh Detection Rules for Ransomware Behaviors
A deep dive into writing custom XML rules and decoders in Wazuh to detect shadow copy deletion, process injection, and vssadmin abuse in real time.
Proactive Threat Hunting using MITRE ATT&CK & Process Lineage Analysis
Learn how to hunt for stealthy persistence and privilege escalation by inspecting parent-child process anomalies in Microsoft Sysmon and EDR logs.