// Blue Team · Detection Engineering · SOC · DFIR

Cybersecurity Student
Blue Team · Detection Engineering · Security Operations

Moinuddin Ahmed · BTL1 Certified (Gold) · #6 India — CyberDefenders

I build practical security projects, write detection rules, investigate incidents, and improve continuously through hands-on labs and real-world challenges.

BTL1 Certified Detection Engineering MITRE ATT&CK Sigma Rules Python SOC Open to Internships

Who I Am

I'm a 3rd-year B.Tech CSE student at SRMIST, Kattankulathur, specializing in Cybersecurity with a clear focus on the Blue Team — detection, investigation, and defense rather than offense for its own sake. Most of what I know came from doing: running labs, breaking down incidents, and rebuilding the reasoning behind each alert until it made sense.

That practice led me toward Detection Engineering specifically — writing and testing the rules that turn raw logs into signal. My Detection Engineering Platform project grew out of wanting to see that pipeline end-to-end: technique, rule, test, validation. It sits alongside smaller tools on my GitHub, including a security operations toolkit and a password-audit utility.

On CyberDefenders I'm ranked #6 in India across Network Forensics, SIEM, Endpoint Forensics, Threat Intelligence, and Malware Analysis, and I completed the SOC Analyst Tier 1 track in April 2026. I hold the BTL1 certification with a 95% score and Gold Coin, and I make a point of showing up to conferences and training where I can — 0xCON Summit among them — to stay close to how working analysts actually think.

An internship at Jamia Darussalam Hospital gave me my first look at defending a live environment: mapping and securing 50+ networked devices with no prior structured inventory. I write up most investigations as technical walkthroughs, and I'm looking to bring that same habit of documentation and testing into a real SOC.

#6
India Rank · CyberDefenders
95%
BTL1 Score · Gold Coin
50+
Labs Completed
100+
Day Streak · TryHackMe

Skills

Detection Engineering
Sigma Rules MITRE ATT&CK Rule Testing False-Positive Tuning
Blue Team
Alert Triage Threat Hunting Incident Response Cyber Kill Chain Diamond Model
Digital Forensics
Autopsy FTK Imager Volatility Wireshark Memory Forensics
SIEM
Splunk (SPL) Wazuh Sysmon DeepBlueCLI Log Analysis
Threat Intelligence
MISP Phishing Analysis Email Headers OSINT TheHive
Programming & Infrastructure
Python Bash Linux Windows Git VMs

Certifications

Deloitte Australia — Cyber Job Simulation
Forage · SOC threat analysis & security advisory tasks · 2024
0xCON Summit 2026
Security conference attendance · Talks & workshops
Microsoft AI Skills Fest
Microsoft · Applied AI skills badge
Networking Basics
Cisco Networking Academy · Foundational networking concepts

Experience

Detection Engineering Platform
Personal Project
2026 — Ongoing
  • Designed a workflow that takes a detection idea from a MITRE ATT&CK technique to a tested Sigma rule, rather than writing rules in isolation
  • Built a testing layer that runs each rule against sample logs to check true-positive coverage before it's considered done
  • Added a validation step to catch obvious false-positive conditions ahead of deployment, so rules ship with a documented rationale
IT & Security Intern
Jamia Darussalam Hospital · Oomerabad, Tamil Nadu
Nov 2024 – Dec 2024
  • Physically located, catalogued, and mapped 50+ networked devices, establishing the hospital's first structured asset inventory
  • Built an asset register with device details, locations, and unique IDs aligned with CIS Controls asset management principles
  • Provided day-to-day support on the Hospital Information System (HIS), including setup, troubleshooting, and user assistance
  • Supported day-to-day IT operations, including server room upkeep, in a live healthcare environment with zero prior downtime attributed to IT changes made during the internship

Security Projects

Detection Engineering Platform
Detection Engineering

Problem: detection rules are often written and shipped without a repeatable way to test them against real behavior. Solution: a workflow that takes a MITRE ATT&CK technique through Sigma authoring, sample log testing, and false-positive review before a rule is considered done. Tech: Python, Sigma, MITRE ATT&CK. Outcome: detections that ship with a tested, documented rationale instead of an assumption.

Threat Research
Threat Intelligence & Analysis

Problem: threat intel is easy to collect but hard to turn into something a defender can act on. Solution: a research repo tracking IOCs, TTPs, and campaign patterns, mapped back to MITRE ATT&CK for use in detection work. Tech: Python, OSINT tooling, MISP. Outcome: a working reference that feeds directly into rule-writing for the Detection Engineering Platform.

Cyber Portal
Security Operations Toolkit

Problem: blue team utilities are usually scattered across single-purpose scripts and browser tabs. Solution: a desktop toolkit that centralizes IOC lookups and threat-assessment utilities behind one interface. Tech: Python, CustomTkinter. Outcome: a reusable base for day-to-day triage tasks instead of rebuilding tooling per investigation.

Password Audit Tool
Offensive Technique Simulation

Problem: weak password policies are hard to evaluate without seeing how they fail under attack. Solution: a GUI tool that simulates brute-force and dictionary attacks, including leetspeak substitutions, against a target policy. Tech: Python. Outcome: a concrete, testable view of where a password policy is weak — used to inform defensive controls, not just describe them.

Cyber Range & Achievements

Blue Team Labs Online
blueteamlabs.online
7
Investigations
5
Challenges
154
Points
Badges earned
Reverser I Intel Analyst I Responder II Challenger II Investigator I
Top 8%
Rank #189,495
45
Rooms Completed
13
Badges
100+
Day Streak
SOC Level 1 Threat Intel Digital Forensics
Track Completed
CyberDefenders · Apr 4, 2026
SOC Analyst Tier 1
30 labs · Easy · Foundational monitoring, detection & escalation skills
Completed

Latest Activity

2026 Attended 0xCON Summit 2026
2026 Built the Detection Engineering Platform
2026 Earned the Microsoft AI Skills Fest badge
2026 Published technical writeups on Network Forensics & Threat Intel investigations
Apr 2026 Completed the SOC Analyst Tier 1 track on CyberDefenders

Let's Connect

I'm always interested in connecting with cybersecurity professionals, recruiters, and teams working in Blue Team, Detection Engineering, and Security Operations.