Skip to content
View pranav-dagay's full-sized avatar

Block or report pranav-dagay

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
pranav-dagay/README.MD

Hi, I'm Pranav Dagay πŸ‘‹

Detection Engineer | SIEM Content Engineering | MITRE ATT&CK-Mapped Detections

πŸ“ Pune, India | πŸ“§ pranavdagay@gmail.com | LinkedIn


About Me

I build detection logic that catches real threats β€” not proof-of-concepts, production content running in live customer environments. I own the full detection engineering pipeline: taking raw logs from a provider, understanding their structure, building normalization layers, and writing MITRE ATT&CK-mapped detections for anomalies, UBA, and DLP on top of them.

I've done this across 10+ enterprise log sources β€” Linux, Windows, Palo Alto, CrowdStrike, Netskope, Zscaler, CyberArk, FortiGate, Kaspersky, Proofpoint, and more β€” each with different log formats, different attacker behaviors, and different failure modes to design around.

I care about detections that survive contact with real data β€” low false-positive rates, clear escalation logic, and documented reasoning an incident responder can trust at 3am.


πŸ” Featured Projects

Project Description Tools
ATT&CK Detection Portfolio (coming soon) Sanitized, from-scratch detection rules mapped to specific MITRE ATT&CK techniques, with documented false-positive analysis Sigma, Python
SIEM Content Engineering Agent (in progress) AI-driven pipeline that automates parser, dictionary, and detection generation for new SIEM log providers Python, LLM agents
BOTS v3 Web Recon Investigation External web reconnaissance and username enumeration attack against a vBulletin forum server Splunk, SPL
BOTS v3 False Positive Triage Cross-sourcetype analysis of anomalous internal host behaviour β€” closed as false positive Splunk, SPL
BOTS v3 SSH Brute Force Investigation DNS anomaly led to confirmed SSH brute force, server compromise, and post-compromise surveillance detection Splunk, SPL
BOTS v3 Empire C2 Investigation Windows Event Log analysis uncovering PowerShell Empire C2 malware on a compromised endpoint Splunk, SPL

πŸ› οΈ Core Strengths

  • Detection Engineering β€” MITRE ATT&CK-mapped detection logic for anomalies, UBA, and DLP; tuned for production false-positive rates
  • Log Normalization β€” Parser & dictionary engineering across 10+ enterprise providers; built to handle malformed, incomplete, and adversarial input
  • Pipeline Ownership β€” Raw log ingestion β†’ normalization β†’ detection, end to end, not just one layer
  • SIEM Platforms β€” Microsoft Sentinel (KQL), IBM QRadar, Splunk (SPL)
  • Engineering β€” Python, Kafka, Redis
  • SOC Workflows β€” Alert triage Β· Severity classification Β· IOC investigation Β· Incident escalation

πŸ“œ Certifications

  • C3SA βœ…
  • Google Cybersecurity (Coursera) βœ…
  • IBM Cybersecurity Badge βœ…
  • CompTIA Security+ (in progress)

Popular repositories Loading

  1. pranav-dagay pranav-dagay Public

    Cybersecurity Graduate | SOC & Defensive Security | Splunk Β· Sentinel Β· QRadar

  2. bots-v3-web-recon-investigation bots-v3-web-recon-investigation Public

    SOC investigation into external web reconnaissance and username enumeration attack against a vBulletin forum server using Splunk BOTS v3.

  3. bots-v3-false-positive-triage bots-v3-false-positive-triage Public

    SOC investigation into anomalous internal host behaviour using Splunk BOTS v3 β€” cross-sourcetype analysis across HTTP, DNS, and Windows endpoint logs leading to a false positive determination.

  4. botsv3-ssh-bruteforce-investigation botsv3-ssh-bruteforce-investigation Public

  5. bots-v3-empire-c2-investigation bots-v3-empire-c2-investigation Public