██╗   ██╗ █████╗ ████████╗███████╗ █████╗ ██╗
 ██║   ██║██╔══██╗╚══██╔══╝██╔════╝██╔══██╗██║
 ██║   ██║███████║   ██║   ███████╗███████║██║
 ╚██╗ ██╔╝██╔══██║   ██║   ╚════██║██╔══██║██║
  ╚████╔╝ ██║  ██║   ██║   ███████║██║  ██║███████╗
   ╚═══╝  ╚═╝  ╚═╝   ╚═╝   ╚══════╝╚═╝  ╚═╝╚══════╝
AVAILABLE FOR OPPORTUNITIES

Vatsal
Sapovadiya

SOC Analyst · Threat Hunter · Incident Responder
Cybersecurity student with hands-on experience in SOC operations, log analysis, phishing triage & SIEM deployment. Building real tools that matter.

4+
PROJECTS
7
CERTS
HTB
ACTIVE
SOC
TIER 1
vatsal@kali-soc: ~/portfolio
PALO ALTO NETWORKS
EC-COUNCIL SOC
CISCO
GOOGLE
SPLUNK SIEM
HARVARD CS50
RED HAT RHEL 9
MITRE ATT&CK
PHISHING ANALYSIS
HONEYPOT OPS
PALO ALTO NETWORKS
EC-COUNCIL SOC
CISCO
GOOGLE
SPLUNK SIEM
HARVARD CS50
RED HAT RHEL 9
MITRE ATT&CK
PHISHING ANALYSIS
HONEYPOT OPS
02 // OPERATIONS CENTER

Live SOC Dashboard

LIVE THREAT FEED0 events
ACTIVE ALERTS3 OPEN
Phishing Email Detected
SPF FAIL · Spoofed domain · T1566.001
OPEN
SSH Brute Force Attempt
47 failed logins · 185.220.x.x · T1110
REVIEW
File Integrity Change
/etc/passwd modified · Wazuh FIM · T1078
REVIEW
Suspicious Process Spawned
cmd.exe from winword.exe · T1059
RESOLVED
Outbound C2 Beacon
Periodic 60s · Port 443 · T1071
RESOLVED
ATTACK ORIGIN (24h)loading...
IOC TRIAGE SIMULATORPowered by threat-intel logic
03 // OPERATIONS LOG

Security Projects

Phishing Email Triage Tool

End-to-end automated phishing analysis platform that parses .eml files, extracts IOCs and enriches them in real-time via VirusTotal, AbuseIPDB & URLScan.io APIs. Features weighted threat scoring (0–100), SPF/DKIM/DMARC detection, and automated MITRE ATT&CK mapping — reducing triage from 30 min to under 60 seconds.

PythonFlaskVirusTotal APIAbuseIPDBURLScan.ioT1566 · T1598 · T1204

Honeypot-Based Cyber Deception System

Deployed a Cowrie SSH honeypot in an isolated lab to capture real-world brute-force attacks, credential harvesting attempts, and attacker command sequences. Analyzed attack timelines and adversary behavior using the MITRE ATT&CK framework.

CowrieSSH HoneypotLinuxThreat IntelligenceT1110 · T1133

SIEM Implementation using Wazuh

Deployed and configured a Wazuh SIEM lab to detect brute-force attempts, malware activity, and file integrity changes across Linux and Windows endpoints. Practiced SOC-style alert triage and the full detection-to-documentation workflow.

WazuhSIEMLinuxWindowsFIMIncident Response

Synthetic Handwriting Security Analysis

Built a GAN-based synthetic handwriting generator to assess document forgery risks, signature spoofing feasibility, and security implications of AI-generated biometric-like data for document authentication systems.

GANPythonDeep LearningBiometric SecurityAI Security Research
04 // ARSENAL

Technical Skills

CORE COMPETENCIES
Security Monitoring
88%
Log Analysis
85%
Alert Triage
82%
Network Analysis
80%
Incident Response
76%
PROGRAMMING
Python
82%
Bash / Shell
70%
Django
65%
SIEM & SECURITY TOOLS
Splunk Wazuh Wireshark VirusTotal AbuseIPDB URLScan.io Cowrie Kali Linux Ubuntu Windows
FRAMEWORKS
MITRE ATT&CK Kill Chain NIST CSF OSINT SOC Operations
PRACTICE PLATFORMS
LetsDefend Hack The Box CyberDefenders CTF Competitions
05 // DEPLOYMENT HISTORY

Experience & Certifications

CAREER TIMELINE
MAY 2025 – JUN 2025
Cybersecurity Intern
CodeAlpha
  • Analyzed live network traffic using Wireshark to identify protocol-level anomalies and brute-force indicators.
  • Investigated packet captures and log data to correlate events and detect unauthorized access.
  • Documented findings in structured SOC-style incident reports.
JUL 2023 – AUG 2023
Android Development Intern
BrainyBeams
  • Developed Android app components using Java/XML in Android Studio.
  • Integrated backend connectivity across multiple device configurations.
SEP 2022 – OCT 2022
Web Development Intern
CreArt Solutions
  • Built a Django-based web app with secure authentication and SMTP email integration.
  • Assisted in security hardening and performance optimization.
2024 – PRESENT
B.Tech – Computer Science & Engineering
CHARUSAT University · CGPA 7.13 (5th Sem)
2021 – 2024
Diploma – Information Technology
Government Polytechnic Rajkot · CGPA 8.6
CERTIFICATIONS
Security Operations Fundamentals
Palo Alto Networks
Into the Trenches: SOC
EC-Council
SOC Fundamentals
Cisco
Introduction to Cybersecurity
Google
Introduction to SIEM
Splunk
CS50: Intro to Cybersecurity
Harvard University
RHEL 9 Fundamentals
Red Hat
vatsal@kali-soc:~$ ./reach_out.sh

Vatsal Sapovadiya

Targeting entry-level SOC Analyst & Cybersecurity Analyst roles.
Open to internships, freelance projects, and collaborative research.
vatsalsapovadiya22@gmail.com

vatsal@kali-soc:~$ echo "Built with a defensive security mindset · 2025"