Prathamesh Sangai
Cybersecurity Analyst — SOC · Digital Forensics · Penetration Testing · Cloud & IT Security
Nearly 3 years of hands-on experience across SOC monitoring, threat detection, incident response, malware analysis, digital forensics, threat hunting, penetration testing, and cloud security. I analyze security alerts, authentication/network activity, and malware behavior with tools like Splunk, Wazuh, ELK, Wireshark, Sysmon, OSQuery, and CrowdStrike Falcon. Based in Philadelphia, PA, and open to full-time roles across SOC Analysis, Cybersecurity Analysis, Digital/Cyber Forensics, Penetration Testing, Cloud Security, and IT Security.
About
I hold an M.S. in Cybersecurity from Drexel University with a 3.93 GPA. Over the past three years I've worked hands-on across SOC monitoring, threat detection, incident response, malware analysis, digital forensics, penetration testing, cloud security, and Microsoft 365 security and AI governance. Right now I'm an IT Support Analyst at Jazz Wireless LLC, where I monitor endpoints for security alerts, run vulnerability assessments, and remediate issues across the business.
Before that I was a Research Assistant in Drexel's Security & Privacy Analytics Lab (SePAL), investigating malware behavior and building YARA/Sigma detection rules mapped to MITRE ATT&CK. And before Drexel, I spent about a year as a Cybercrime Investigator in India, working fraud and identity-theft cases with CID Pune Police and DGGI using tools like Cellebrite, FTK Imager, and Magnet AXIOM.
Outside of work I build my own tools. Right now that's an AI-assisted Android malware analysis sandbox with evidence-driven risk scoring, plus a job-application tracker that parses my own inbox so nothing slips through the cracks during this search.
- locationPhiladelphia, PA
- degreeM.S. Cybersecurity, Drexel (3.93 GPA)
- focusSOC · Forensics · Pentesting · Cloud Security
- labSePAL — Drexel Security & Privacy Analytics Lab (2025)
- statusOpen to full-time roles
- languagesPython, C, C++, Java, Shell, SQL
Experience
- Provide technical support and troubleshooting for desktops, laptops, and networking equipment across multiple business locations, resolving Windows OS and application issues to minimize employee downtime.
- Monitor endpoint devices for security alerts, malware, and unauthorized access, performing detection and remediation to reduce the company's exposure to active threats.
- Support vulnerability assessments and remediate identified security issues, including OS updates, patches, antivirus, and endpoint protection software, to maintain consistent protection against emerging threats.
- Manage user accounts, access permissions, and MFA setup; investigate and resolve technical/security incidents; and maintain IT asset inventory and backup support processes to keep systems secure, tracked, and audit-ready.
- Investigated malware behavior, security events, IOCs, persistence mechanisms, payload execution, and network traffic (including TLS/QUIC) across Android and Windows environments to support ongoing threat research.
- Developed YARA and Sigma detection rules and built Frida hooks/Xposed modules to identify malware behaviors and monitor sensitive application activity, improving simulated-threat detection coverage.
- Performed threat hunting and behavioral analysis using system, application, and network artifacts, surfacing anomalous activity and attacker techniques for further investigation.
- Mapped malware behaviors to MITRE ATT&CK TTPs and documented findings in reproducible security analysis reports, supporting structured threat analysis across the lab.
- Supported cybercrime investigations involving fraud, identity theft, and compromised devices in coordination with CID Pune Police and DGGI, contributing to active law enforcement casework.
- Performed digital forensic acquisition, imaging, and artifact extraction across mobile and computer systems using Cellebrite/UFED, FTK Imager, Magnet AXIOM, and Splunk, preserving evidence integrity for investigations.
- Analyzed and correlated firewall, proxy, application, and system logs, and investigated digital artifacts, to identify indicators of compromise and reconstruct suspicious activity timelines.
- Maintained chain-of-custody documentation and forensic reports, ensuring evidence remained admissible for legal and investigative proceedings.
Projects
- Engineered a modular Android malware analysis sandbox (Python, FastAPI) to automate APK static and emulator-based dynamic analysis, using ADB and Android Emulator workflows to install, launch, and observe applications while collecting permissions, components, processes, filesystem, network, intent, and logcat evidence.
- Built evidence-driven risk scoring and correlation pipelines that combine static and runtime findings into severity-ranked, explainable assessments, giving analysts a clear, evidence-backed view of malware risk.
- Implemented AI-assisted analyst reporting that converts collected evidence into structured executive summaries, technical findings, and recommended investigation steps without introducing unsupported conclusions.
- Improved detection quality by filtering unrelated runtime logs and reducing false positives, validating platform reliability through 38+ Pytest end-to-end and regression tests.
- A local, Gmail-based job-application tracker that reads confirmations, recruiter messages, assessments, interviews, rejections, and offers — and derives live application status automatically.
- Built around one rule: no job-related message is ever silently dropped. Every message links to an application, creates one, or lands in a review queue.
- Read-only Gmail OAuth throughout — no send or delete access, ever.
- Built an end-to-end Windows SOC lab using Sysmon, Windows Security auditing, Splunk Cloud, HEC, and structured JSON telemetry to collect and analyze endpoint activity.
- Developed and validated 5 custom SPL detections for suspicious/encoded PowerShell, PowerShell-to-CMD execution, repeated failed logons, and successful authentication following repeated failures.
- Correlated Windows Event IDs 4624/4625, investigated authentication activity, mapped detections to MITRE ATT&CK techniques including T1059.001, T1027, T1110, and T1078, and documented analyst disposition.
- Built a Splunk SOC dashboard to monitor detection activity, authentication events, PowerShell behavior, MITRE ATT&CK coverage, and investigation evidence.
- Built a simulated Microsoft 365 environment to evaluate AI governance, data protection, and information-access risk using Microsoft Purview and native M365 security controls.
- Configured DLP policies, sensitivity labels, and retention policies, and used PowerShell, Microsoft Graph API, and KQL to review audit logs and identify oversharing and data-exposure risks.
- Built Power BI dashboards to track compliance posture and evaluated Copilot-related oversharing scenarios across the simulated tenant.
- Built a SOC lab using Splunk and Wazuh to generate alerts mapped to MITRE ATT&CK techniques, creating a realistic environment for detection engineering practice.
- Conducted log analysis and threat hunting to identify anomalous authentication and network behavior, sharpening hands-on SOC analyst workflows.
- Tuned detection rules to reduce false positives, improving alert fidelity and analyst efficiency across simulated incidents.
- Documented investigation workflows and incident response steps, producing a repeatable playbook for SOC analysis and training.
- Performed OWASP Top-10 testing on DVWA and Juice Shop using Burp Suite, Nmap, and Metasploit, simulating real-world attack scenarios against vulnerable applications.
- Identified XSS, SQL injection, and authentication flaws with proof-of-concept exploitation, demonstrating real business impact of each vulnerability.
- Documented vulnerability impact, severity levels, and remediation recommendations, giving developers a clear path to resolve identified issues.
- Developed an encrypted chat system using QUIC and TLS 1.3 with FastAPI-based authentication, delivering a secure, low-latency communication platform.
- Implemented secure key exchange and session handling logic, enabling reliable communication without compromising security guarantees.
- Analyzed protocol handshakes and packet flows to validate encryption integrity, confirming the system met its security design goals.
Write-ups
Problem
Manual Android malware triage is slow and inconsistent. Analysts run static and dynamic analysis separately, then correlate scattered evidence by hand. Without a repeatable structure, both the speed and the reliability of the conclusions suffer.
Method
I built a modular sandbox in Python and FastAPI that automates both APK static inspection and emulator-based dynamic analysis through ADB, collecting permissions, components, processes, filesystem, network, intent, and logcat evidence. Static and runtime findings get correlated into a severity-ranked risk score. On top of that sits an AI-assisted reporting layer that turns raw evidence into structured summaries and findings, without adding conclusions the evidence doesn't actually support. I validated reliability with 38+ Pytest end-to-end and regression tests, and filtered out unrelated runtime logs to cut down false positives.
Outcome
The result is one pipeline that takes a raw APK all the way to an evidence-backed, severity-ranked risk assessment and a structured analyst report. What used to be manual, inconsistent triage is now a process I can repeat, test, and trust.
Problem
Practicing real SOC workflows needs realistic alert data mapped to real attacker techniques. Most training environments rely on toy datasets that don't tie back to a recognized framework, so it's hard to practice genuine triage and tuning decisions.
Method
I built a lab with Splunk and Wazuh that generates alerts mapped explicitly to MITRE ATT&CK techniques. From there I ran log analysis and threat hunting against the simulated environment to surface anomalous authentication and network behavior, and iterated on detection rules to cut false positives. Alert fidelity mattered as much as detection coverage throughout.
Outcome
What came out of it is a documented, repeatable playbook for SOC investigation and detection tuning, with MITRE-mapped alerting and a measurable drop in false positives — the kind of before/after result that's directly transferable to a live SOC.
Skills
Security Operations & SOC
SIEM & Security Monitoring
Threat Detection & Frameworks
Digital Forensics & DFIR
Malware Analysis & Reverse Engineering
Network & Security
Vulnerability Assessment & Penetration Testing
Cloud, Identity & Infrastructure Security
Microsoft 365 Security & AI Governance
Programming & Scripting
Certifications
Contact
Open to full-time roles in SOC Analysis, Cybersecurity Analysis, Digital/Cyber Forensics, Penetration Testing, Cloud Security, and IT Security — reach out directly, I respond fast.