Prathamesh Sangai

Cybersecurity Analyst — SOC · Digital Forensics · Penetration Testing · Cloud & IT Security

Nearly 3 years of hands-on experience across SOC monitoring, threat detection, incident response, malware analysis, digital forensics, threat hunting, penetration testing, and cloud security. I analyze security alerts, authentication/network activity, and malware behavior with tools like Splunk, Wazuh, ELK, Wireshark, Sysmon, OSQuery, and CrowdStrike Falcon. Based in Philadelphia, PA, and open to full-time roles across SOC Analysis, Cybersecurity Analysis, Digital/Cyber Forensics, Penetration Testing, Cloud Security, and IT Security.

~/about $ cat profile.md

About

I hold an M.S. in Cybersecurity from Drexel University with a 3.93 GPA. Over the past three years I've worked hands-on across SOC monitoring, threat detection, incident response, malware analysis, digital forensics, penetration testing, cloud security, and Microsoft 365 security and AI governance. Right now I'm an IT Support Analyst at Jazz Wireless LLC, where I monitor endpoints for security alerts, run vulnerability assessments, and remediate issues across the business.

Before that I was a Research Assistant in Drexel's Security & Privacy Analytics Lab (SePAL), investigating malware behavior and building YARA/Sigma detection rules mapped to MITRE ATT&CK. And before Drexel, I spent about a year as a Cybercrime Investigator in India, working fraud and identity-theft cases with CID Pune Police and DGGI using tools like Cellebrite, FTK Imager, and Magnet AXIOM.

Outside of work I build my own tools. Right now that's an AI-assisted Android malware analysis sandbox with evidence-driven risk scoring, plus a job-application tracker that parses my own inbox so nothing slips through the cracks during this search.

M.S. in Cybersecurity — Drexel University
Philadelphia, PA · Dec 2025 · GPA 3.93
Focus: Malware Analysis, Digital Forensics, Cloud Security, Network Defense, Cryptography
B.Tech in Information Technology — VIIT
Pune, India · Aug 2019 – Jun 2023
  • locationPhiladelphia, PA
  • degreeM.S. Cybersecurity, Drexel (3.93 GPA)
  • focusSOC · Forensics · Pentesting · Cloud Security
  • labSePAL — Drexel Security & Privacy Analytics Lab (2025)
  • statusOpen to full-time roles
  • languagesPython, C, C++, Java, Shell, SQL
~/experience $ tail -f career.log

Experience

Aug 2026 — Present
IT Support Analyst current
Jazz Wireless LLC · Philadelphia, PA
  • Provide technical support and troubleshooting for desktops, laptops, and networking equipment across multiple business locations, resolving Windows OS and application issues to minimize employee downtime.
  • Monitor endpoint devices for security alerts, malware, and unauthorized access, performing detection and remediation to reduce the company's exposure to active threats.
  • Support vulnerability assessments and remediate identified security issues, including OS updates, patches, antivirus, and endpoint protection software, to maintain consistent protection against emerging threats.
  • Manage user accounts, access permissions, and MFA setup; investigate and resolve technical/security incidents; and maintain IT asset inventory and backup support processes to keep systems secure, tracked, and audit-ready.
Jan 2025 — Dec 2025
Research Assistant — Cybersecurity & Malware Analysis
Drexel University — Security & Privacy Analytics Lab (SePAL) · Philadelphia, PA
  • Investigated malware behavior, security events, IOCs, persistence mechanisms, payload execution, and network traffic (including TLS/QUIC) across Android and Windows environments to support ongoing threat research.
  • Developed YARA and Sigma detection rules and built Frida hooks/Xposed modules to identify malware behaviors and monitor sensitive application activity, improving simulated-threat detection coverage.
  • Performed threat hunting and behavioral analysis using system, application, and network artifacts, surfacing anomalous activity and attacker techniques for further investigation.
  • Mapped malware behaviors to MITRE ATT&CK TTPs and documented findings in reproducible security analysis reports, supporting structured threat analysis across the lab.
Aug 2022 — Nov 2023
Cybercrime Investigator Intern
Sana Cyber Forensics · Maharashtra, India
  • Supported cybercrime investigations involving fraud, identity theft, and compromised devices in coordination with CID Pune Police and DGGI, contributing to active law enforcement casework.
  • Performed digital forensic acquisition, imaging, and artifact extraction across mobile and computer systems using Cellebrite/UFED, FTK Imager, Magnet AXIOM, and Splunk, preserving evidence integrity for investigations.
  • Analyzed and correlated firewall, proxy, application, and system logs, and investigated digital artifacts, to identify indicators of compromise and reconstruct suspicious activity timelines.
  • Maintained chain-of-custody documentation and forensic reports, ensuring evidence remained admissible for legal and investigative proceedings.
~/projects $ ls -la ./case-files

Projects

CASE_ID: PS-2026-01 in progress
AndroAI Sandbox
Jun 2026 — Present
  • Engineered a modular Android malware analysis sandbox (Python, FastAPI) to automate APK static and emulator-based dynamic analysis, using ADB and Android Emulator workflows to install, launch, and observe applications while collecting permissions, components, processes, filesystem, network, intent, and logcat evidence.
  • Built evidence-driven risk scoring and correlation pipelines that combine static and runtime findings into severity-ranked, explainable assessments, giving analysts a clear, evidence-backed view of malware risk.
  • Implemented AI-assisted analyst reporting that converts collected evidence into structured executive summaries, technical findings, and recommended investigation steps without introducing unsupported conclusions.
  • Improved detection quality by filtering unrelated runtime logs and reducing false positives, validating platform reliability through 38+ Pytest end-to-end and regression tests.
PythonFastAPIADBAndroid EmulatorPytestRisk Scoring
CASE_ID: PS-2026-02 in progress
JobTrace
2026
  • A local, Gmail-based job-application tracker that reads confirmations, recruiter messages, assessments, interviews, rejections, and offers — and derives live application status automatically.
  • Built around one rule: no job-related message is ever silently dropped. Every message links to an application, creates one, or lands in a review queue.
  • Read-only Gmail OAuth throughout — no send or delete access, ever.
PythonFastAPISQLiteGmail API
CASE_ID: PS-2026-03 completed
SOC Detection Engineering & Incident Investigation Lab
Jun 2026 — Aug 2026
  • Built an end-to-end Windows SOC lab using Sysmon, Windows Security auditing, Splunk Cloud, HEC, and structured JSON telemetry to collect and analyze endpoint activity.
  • Developed and validated 5 custom SPL detections for suspicious/encoded PowerShell, PowerShell-to-CMD execution, repeated failed logons, and successful authentication following repeated failures.
  • Correlated Windows Event IDs 4624/4625, investigated authentication activity, mapped detections to MITRE ATT&CK techniques including T1059.001, T1027, T1110, and T1078, and documented analyst disposition.
  • Built a Splunk SOC dashboard to monitor detection activity, authentication events, PowerShell behavior, MITRE ATT&CK coverage, and investigation evidence.
↗ View on GitHub
Splunk CloudSPLSysmonWindows Security LogsPowerShellHECMITRE ATT&CK
CASE_ID: PS-2025-04 completed
Microsoft 365 AI Governance Lab
2025 — 2026
  • Built a simulated Microsoft 365 environment to evaluate AI governance, data protection, and information-access risk using Microsoft Purview and native M365 security controls.
  • Configured DLP policies, sensitivity labels, and retention policies, and used PowerShell, Microsoft Graph API, and KQL to review audit logs and identify oversharing and data-exposure risks.
  • Built Power BI dashboards to track compliance posture and evaluated Copilot-related oversharing scenarios across the simulated tenant.
Microsoft PurviewDLPSensitivity LabelsPowerShellMicrosoft Graph APIKQLPower BI
CASE_ID: PS-2025-05 completed
SOC Incident Simulation Lab
Feb 2025 — May 2025
  • Built a SOC lab using Splunk and Wazuh to generate alerts mapped to MITRE ATT&CK techniques, creating a realistic environment for detection engineering practice.
  • Conducted log analysis and threat hunting to identify anomalous authentication and network behavior, sharpening hands-on SOC analyst workflows.
  • Tuned detection rules to reduce false positives, improving alert fidelity and analyst efficiency across simulated incidents.
  • Documented investigation workflows and incident response steps, producing a repeatable playbook for SOC analysis and training.
SplunkWazuhMITRE ATT&CK
CASE_ID: PS-2024-06 completed
Web Application Penetration Testing Lab
Sep 2024 — Jan 2025
  • Performed OWASP Top-10 testing on DVWA and Juice Shop using Burp Suite, Nmap, and Metasploit, simulating real-world attack scenarios against vulnerable applications.
  • Identified XSS, SQL injection, and authentication flaws with proof-of-concept exploitation, demonstrating real business impact of each vulnerability.
  • Documented vulnerability impact, severity levels, and remediation recommendations, giving developers a clear path to resolve identified issues.
Burp SuiteNmapMetasploitOWASP Top-10
CASE_ID: PS-2024-07 completed
QUIC Secure Chat Application
Apr 2024 — Jul 2024
  • Developed an encrypted chat system using QUIC and TLS 1.3 with FastAPI-based authentication, delivering a secure, low-latency communication platform.
  • Implemented secure key exchange and session handling logic, enabling reliable communication without compromising security guarantees.
  • Analyzed protocol handshakes and packet flows to validate encryption integrity, confirming the system met its security design goals.
QUICTLS 1.3FastAPI
~/writeups $ cat case-studies.md

Write-ups

AndroAI Sandbox — From Raw APK to Evidence-Backed Verdict
Personal project · Jun 2026 — Present

Problem

Manual Android malware triage is slow and inconsistent. Analysts run static and dynamic analysis separately, then correlate scattered evidence by hand. Without a repeatable structure, both the speed and the reliability of the conclusions suffer.

Method

I built a modular sandbox in Python and FastAPI that automates both APK static inspection and emulator-based dynamic analysis through ADB, collecting permissions, components, processes, filesystem, network, intent, and logcat evidence. Static and runtime findings get correlated into a severity-ranked risk score. On top of that sits an AI-assisted reporting layer that turns raw evidence into structured summaries and findings, without adding conclusions the evidence doesn't actually support. I validated reliability with 38+ Pytest end-to-end and regression tests, and filtered out unrelated runtime logs to cut down false positives.

Outcome

The result is one pipeline that takes a raw APK all the way to an evidence-backed, severity-ranked risk assessment and a structured analyst report. What used to be manual, inconsistent triage is now a process I can repeat, test, and trust.

SOC Incident Simulation Lab — Detection Tuning Against MITRE ATT&CK
Personal project · 2025

Problem

Practicing real SOC workflows needs realistic alert data mapped to real attacker techniques. Most training environments rely on toy datasets that don't tie back to a recognized framework, so it's hard to practice genuine triage and tuning decisions.

Method

I built a lab with Splunk and Wazuh that generates alerts mapped explicitly to MITRE ATT&CK techniques. From there I ran log analysis and threat hunting against the simulated environment to surface anomalous authentication and network behavior, and iterated on detection rules to cut false positives. Alert fidelity mattered as much as detection coverage throughout.

Outcome

What came out of it is a documented, repeatable playbook for SOC investigation and detection tuning, with MITRE-mapped alerting and a measurable drop in false positives — the kind of before/after result that's directly transferable to a live SOC.

~/skills $ cat loadout.yaml

Skills

Security Operations & SOC

SIEMSecurity MonitoringAlert TriageThreat DetectionDetection EngineeringIncident ResponseIncident InvestigationThreat HuntingThreat IntelligenceLog AnalysisIOC AnalysisMalware DetectionSecurity Event CorrelationFalse Positive AnalysisEndpoint SecurityMulti-Factor Authentication (MFA)

SIEM & Security Monitoring

SplunkWazuhELK StackCrowdStrike FalconSysmonOSQueryWireshark

Threat Detection & Frameworks

MITRE ATT&CKYARASigmaIOC/IOA AnalysisTTP AnalysisNIST CSFOWASP Top 10

Digital Forensics & DFIR

Digital ForensicsComputer ForensicsMobile ForensicsEvidence CollectionForensic ImagingArtifact AnalysisTimeline AnalysisChain of CustodyFTK ImagerMagnet AXIOMCellebriteAutopsy

Malware Analysis & Reverse Engineering

Static AnalysisDynamic AnalysisBehavioral AnalysisMalware ClassificationPersistence AnalysisPayload AnalysisNetwork Exfiltration AnalysisFridaXposed

Network & Security

TCP/IPDNSHTTP/HTTPSTLSQUICFirewall LogsProxy LogsNetwork Traffic AnalysisPacket Analysis

Vulnerability Assessment & Penetration Testing

NmapBurp SuiteMetasploitOWASP ZAPNessusNiktoWeb Application SecurityVulnerability Assessment

Cloud, Identity & Infrastructure Security

AWS IAMAWS EC2AWS S3CloudTrailDockerCloud Security

Microsoft 365 Security & AI Governance

Microsoft 365 SecurityMicrosoft PurviewAI GovernanceData Loss Prevention (DLP)Sensitivity LabelsRetention PoliciesAudit LogsKQLPowerShellMicrosoft Graph APIPower BI

Programming & Scripting

PythonShellCC++JavaSQLLinuxCryptography
~/certifications $ cat credentials.log

Certifications

Ethical Hacking Essentials (EHE)
EC-Council
✓ EARNED
Digital Forensics Essentials (DFE)
EC-Council
✓ EARNED
Introduction to Cybersecurity
Cisco
✓ EARNED
Career Essentials in Cybersecurity
Microsoft & LinkedIn
✓ EARNED
Security+
CompTIA
IN PROGRESS
Leadership
Advisory Board Member, Entrepreneurship Development Cell (EDC), VIIT — Sep 2022 – Dec 2023. Documentation & Design Head, MIC.IIC.VIIT.
~/contact $ ./reach_out.sh

Contact

Open to full-time roles in SOC Analysis, Cybersecurity Analysis, Digital/Cyber Forensics, Penetration Testing, Cloud Security, and IT Security — reach out directly, I respond fast.