👋Hello, I'mBinod Rawat

⚡Specialized in SOC Operations, Threat Hunting, Detection Engineering, and Incident Response.

SOC Operations (Tier 1-3)
Threat Hunting
EDR/XDR and NG-SIEM
Memory & Host Forensics
500+
Alerts Triaged & Investigated
Multi-stage SOC alerts analyzed across SIEM and EDR platforms.
20+
Custom Detection Rules
Crowdsrike correlation rules authored using CQL and deployed into production SIEM.
99.8%
Incident SLA Compliance
Consistently meeting P1/P2 incident detection & response SLAs.
40+
Threat Hunts Conducted
Proactive hypothesis-driven hunts based on MITRE ATT&CK TTPs.
Core Expertise

Featured Security Capabilities

View All Skills

Threat Hunting

Hypothesis-driven threat hunting targeting persistence, privilege escalation, and lateral movement.

Verified Competency

Detection Engineering

Designing, testing, and tuning high-fidelity detection rules mapped to MITRE ATT&CK.

Verified Competency

Incident Response

End-to-end incident handling, root-cause analysis, containment, and eradication playbooks.

Verified Competency

MITRE ATT&CK Framework

Mapping adversary TTPs, gap analysis, and defense validation across enterprise matrix.

Verified Competency

Wazuh SIEM

Architecting open-source XDR/SIEM, agent deployment, XML rule tuning, and decoder writing.

Verified Competency

CrowdStrike Falcon

EDR telemetry monitoring, custom IOA creation, real-time response (RTR), and host isolation.

Verified Competency
Validated Knowledge

Industry Credentials

All Certifications
CR

Falcon Administrator

CrowdStrike University • 2026-05

LP33487
CR

Incident Responder

CrowdStrike University • 2026-07

LP37163
CR

Threat Hunter

CrowdStrike University • 2026-06

LP35548
Knowledge Sharing

Recent Technical Articles

Read Blog
Detection Engineering•7 min read

Building Production-Grade Wazuh Detection Rules for Ransomware Behaviors

A deep dive into writing custom XML rules and decoders in Wazuh to detect shadow copy deletion, process injection, and vssadmin abuse in real time.

Read Technical Case Study
Threat Hunting•10 min read

Proactive Threat Hunting using MITRE ATT&CK & Process Lineage Analysis

Learn how to hunt for stealthy persistence and privilege escalation by inspecting parent-child process anomalies in Microsoft Sysmon and EDR logs.

Read Technical Case Study