status: monitoring

Hi, I'm Himangshu Pan.

Blue-team research · Detection · Incident response. I investigate logs, build detections, and write up what I learn so others can use it.

Himangshu Pan at a SOC analyst workstation surrounded by dashboards, detection alerts, and the motto: detect · analyze · respond

$ work in silence — let your detections make the noise

sheru@soc:~
sheru@soc:~$ whoami --verbose
himangshu.pan
role: SOC analyst (blue team)
focus: detection · IR · log analysis
status: open to opportunities

# about

Python developer turned defensive security researcher. After several years building Python backends and blockchain systems, I pivoted into security with a focus on the blue team — detection engineering, incident response, and the daily craft of running a SOC.

I spend my time in labs reproducing attacker behavior so I can write better detections for it, picking apart logs, and turning CTF rooms into transferable analyst muscle. CEH (2018) was my entry point; the work since has been about understanding systems deeply enough to defend them, not just probe them.

# skills

SIEM & Log Analysis

Splunk ELK / OpenSearch Wazuh KQL Sigma rules

Network Forensics

Wireshark tcpdump Zeek Suricata PCAP triage

Endpoint & EDR

Sysmon MS Defender Velociraptor OSQuery

Scripting & Automation

Python Bash PowerShell Regex API enrichment

Frameworks

MITRE ATT&CK D3FEND NIST CSF Cyber Kill Chain

Lab & Tooling

Linux VMware Docker Git Ghidra (basics)

# certifications

Certified Ethical Hacker (CEH)

EC-Council

2018

$ more in progress — BTL1, Security+, KC7.

# recent writeups

all writeups →

# projects

all projects →