Detection Engineer | SIEM Content Engineering | MITRE ATT&CK-Mapped Detections
π Pune, India | π§ pranavdagay@gmail.com | LinkedIn
I build detection logic that catches real threats β not proof-of-concepts, production content running in live customer environments. I own the full detection engineering pipeline: taking raw logs from a provider, understanding their structure, building normalization layers, and writing MITRE ATT&CK-mapped detections for anomalies, UBA, and DLP on top of them.
I've done this across 10+ enterprise log sources β Linux, Windows, Palo Alto, CrowdStrike, Netskope, Zscaler, CyberArk, FortiGate, Kaspersky, Proofpoint, and more β each with different log formats, different attacker behaviors, and different failure modes to design around.
I care about detections that survive contact with real data β low false-positive rates, clear escalation logic, and documented reasoning an incident responder can trust at 3am.
| Project | Description | Tools |
|---|---|---|
| ATT&CK Detection Portfolio (coming soon) | Sanitized, from-scratch detection rules mapped to specific MITRE ATT&CK techniques, with documented false-positive analysis | Sigma, Python |
| SIEM Content Engineering Agent (in progress) | AI-driven pipeline that automates parser, dictionary, and detection generation for new SIEM log providers | Python, LLM agents |
| BOTS v3 Web Recon Investigation | External web reconnaissance and username enumeration attack against a vBulletin forum server | Splunk, SPL |
| BOTS v3 False Positive Triage | Cross-sourcetype analysis of anomalous internal host behaviour β closed as false positive | Splunk, SPL |
| BOTS v3 SSH Brute Force Investigation | DNS anomaly led to confirmed SSH brute force, server compromise, and post-compromise surveillance detection | Splunk, SPL |
| BOTS v3 Empire C2 Investigation | Windows Event Log analysis uncovering PowerShell Empire C2 malware on a compromised endpoint | Splunk, SPL |
- Detection Engineering β MITRE ATT&CK-mapped detection logic for anomalies, UBA, and DLP; tuned for production false-positive rates
- Log Normalization β Parser & dictionary engineering across 10+ enterprise providers; built to handle malformed, incomplete, and adversarial input
- Pipeline Ownership β Raw log ingestion β normalization β detection, end to end, not just one layer
- SIEM Platforms β Microsoft Sentinel (KQL), IBM QRadar, Splunk (SPL)
- Engineering β Python, Kafka, Redis
- SOC Workflows β Alert triage Β· Severity classification Β· IOC investigation Β· Incident escalation
- C3SA β
- Google Cybersecurity (Coursera) β
- IBM Cybersecurity Badge β
- CompTIA Security+ (in progress)