Incident Response Engineer | DFIR | Cloud Security | Detection Engineering
I investigate security incidents, build detection logic, and improve SOC response workflows across endpoint, identity, cloud, and network telemetry.
LinkedIn: linkedin.com/in/yuvvraaj
Email: yuvrajsingh3440@gmail.com
My GitHub portfolio highlights practical security engineering work: detection content, incident response workflows, cloud security labs, and automation for security operations.
I am especially focused on:
- Incident response and DFIR investigations
- Ransomware preparation, containment, and recovery support
- Detection engineering and threat hunting logic
- Cloud security monitoring across AWS, Azure, and GCP
- SOC automation, enrichment, reporting, and playbook development
A tool-neutral detection engineering content library designed for SIEM, EDR, XDR, data lake, and security analytics platforms.
This repository demonstrates how I approach detection engineering from an incident-response perspective: reusable logic, clear data-source assumptions, watchlist handling, validation, and tuning guidance.
Highlights:
- Portable analytic rule templates that are not tied to one vendor
- Ransomware intrusion detection pack covering privilege escalation, credential theft, lateral movement, backup tampering, staging, exfiltration, and encryption behavior
- Public threat-intelligence IOC correlation templates
- Hunting queries for incident response and threat detection
- Parser and connector guidance for normalized telemetry
- Validation structure to reduce sensitive-content and quality issues
Core concepts used in the repo include EndpointTelemetry, PublicIOCs, normalized watchlists, and correlation-first detection design.
SecureInteli Technologies | Mar 2025 - Present
- Lead and support investigations across AWS, Azure, GCP, endpoint, identity, and network telemetry.
- Tune SIEM and EDR detections to improve signal quality and reduce false positives.
- Build Python-based enrichment workflows for cloud security findings and MDR triage.
- Create SOC dashboards, response reports, playbooks, and detection-readiness material.
SafeAeon | Jun 2024 - Dec 2024
- Triaged high-volume MDR alerts and resolved incidents across SIEM, EDR, and cloud telemetry.
- Investigated phishing, suspicious execution, credential misuse, malware activity, and cloud misconfigurations.
- Supported ransomware investigations through evidence review, scope analysis, and response coordination.
- Built threat-intelligence enrichment scripts to reduce manual triage effort.
- Incident Response: triage, containment coordination, escalation, root-cause analysis, reporting
- Detection Engineering: SIEM tuning, hunting logic, rule validation, use-case development
- Cloud Security: AWS, Azure, GCP, cloud-native alerts, hybrid environment investigations
- Threat Investigation: ransomware, phishing, credential misuse, malware triage, insider-threat indicators
- Automation: Python, Bash, SQL, enrichment workflows, operational reporting
- Frameworks: MITRE ATT&CK, NIST, OWASP Top 10, ISO 27001
Built an Active Directory and AWS-based cyber range for attack simulation, cloud investigation practice, and incident response exercises.
Developed a framework for AI-system incident response covering threat taxonomy, severity matrix, AI-specific TTPs/IOCs, compliance mapping, and tabletop-ready playbooks.
VIT Bhopal University
Integrated M.Tech in Computer Science Engineering, Cybersecurity Specialization
Certifications
- CEH
- ISO 27001:2022 Lead Auditor
- Speaker at AI-SEC Community on Incident Response for AI Systems
- Finalist, DRDO Defence Start-up Hackathon

