LOADING SECURITY MODULES
About Skills Projects Toolkit Experience Certifications Education Contact
Open to Opportunities
access granted — you've reached

Om Patel

$> 

Detecting threats. Investigating attacks. Securing systems.

SCROLL

Who I Am

Available Immediately

Cybersecurity Analyst with hands-on experience in SOC operations, incident response, EDR detection engineering, and vulnerability management. M.Eng. in Information Systems Security from Concordia University, Montreal.

Cisco CyberOps, Fortinet FCSS, and Qualys VMDR certified — actively targeting SOC Analyst roles across Canada. I thrive at the intersection of threat intelligence and operational defence, turning raw alert data into decisive, time-boxed incident response.

analyst_profile.sh
om@soc:~$ cat profile.json
{
  "location"     : "Canada 🍁",
  "mission"      : "Hunt threats. Kill chains. Secure systems.",
  "open_to"      : ["Cybersecurity Analyst", "SOC Analyst", "Detection Eng"],
  "response_time": "< 4h MTTR on confirmed incidents"
}
0
Daily Alerts Triaged
0
Incidents Responded
0
Systems Assessed
0
Certifications Held
OM-SEC // OPERATIVE ID
OM PATEL
CYBERSECURITY ANALYST
UNITSOC / DFIR
BASECANADA
CLEARANCELEVEL 5
STATUSACTIVE — DEPLOYABLE
ID: 0M-P4T3L-2026 · ISSUED BY: THE SOC

Technical Arsenal

Detection & SOC
SIEM (Splunk/ELK) Alert Triage Threat Hunting Threat Intelligence IDS/IPS Incident Response Network Monitoring
Endpoint & EDR
LimaCharlie EDR Detection Engineering MITRE ATT&CK Malware Triage PowerShell Forensics Active Directory
Vulnerability Management
Qualys VMDR Vulnerability Assessment Risk Assessment Security Audits Compliance
Tools & Languages
Wireshark Nmap Kali Linux Burp Suite Redline VirusTotal PowerShell Python Bash Firewall Admin
Frameworks & Standards
MITRE ATT&CK NIST CSF ISO 27001 CIS Controls OWASP Top 10

Lab Work

Endpoint Detection & Response Lab — LimaCharlie EDR
EDR MITRE ATT&CK Detection Engineering Windows

Engineered a complete attack-detect-investigate cycle by deploying LimaCharlie EDR on Windows, simulating LSASS credential dumping (MITRE ATT&CK T1003.001) via rundll32/comsvcs.dll, and triggering 4 high-severity detections. Authored custom behavioral detection rules, triaged all alerts, and produced a formal SOC investigation report with full IOC mapping.

alert_triage.log
[HIGH] LSASS memory access via rundll32
[HIGH] T1003.001 — Credential Dumping
[IOC] comsvcs.dll MiniDump detected
[+] 4 detections mapped & closed
AWS IAM Access Key Lifecycle Enforcement
AWS IAM Cloud Security Automation Python

Designed and deployed an automated IAM governance workflow that enumerates 20+ user accounts, flags non-compliant long-lived access keys, and enforces automated deactivation — eliminating cloud credential risk with zero manual intervention. Implemented least-privilege IAM policies with SES-based real-time alerting.

iam_enforcer.py
$ python enforce_iam.py --scan
Scanning 20+ IAM accounts...
[!] 3 stale keys found (>90 days)
[+] Auto-deactivated. SES alert sent.

SOC Toolkit

Not screenshots — working tools, built from scratch, running entirely in your browser. The same analysis I do daily, miniaturized. Try them.

// output appears here — IPs, domains, URLs, emails, MD5/SHA1/SHA256 hashes
—
// red flags will be itemized here with severity
awaiting input…
// entropy, charset, offline & online attack estimates
// detection + decoded output. JWTs get fully unpacked.

Work History

Cybersecurity Analyst
Jul 2023 – Jul 2024
Welwin Infotech Limited
Vadodara, India
  • Triaged 50+ daily SIEM alerts across multi-tenant environments, classifying phishing, malware, unauthorized access, and traffic anomalies.
  • Participated in incident response for 15+ confirmed security incidents — supporting containment, eradication, and recovery workflows while independently authoring post-incident reports documenting root cause, attack timeline, and remediation steps.
  • Executed vulnerability assessments across 20+ environments, uncovering 10+ critical findings that directly resulted in patches.
  • Monitored endpoint and network traffic continuously using IDS/IPS, EDR telemetry, and packet-level analysis.
  • Translated complex findings into clear executive briefings that prompted concrete remediation action.
Cybersecurity Analyst Internship
Jun 2023 · 1 mo
Welwin Infotech Limited
Vadodara, India
  • Conducted vulnerability assessments and performed security audits to identify gaps in the organization's security posture.
  • Assisted in the development and documentation of security policies aligned with industry best practices.
  • Gained hands-on exposure to network monitoring and incident response workflows in a live environment.
  • Collaborated with cross-functional teams to assess and mitigate security risks across systems and processes.
Cybersecurity Specialist (Volunteer)
Jan 2023 – Dec 2024
MHA Cyber Volunteer Program — Gujarat Police CID
India (Remote)
  • Registered under Ministry of Home Affairs national Cyber Volunteer portal, supporting law enforcement combating cybercrime.
  • Reported 30+ instances of malicious online content to law enforcement via official MHA cybercrime reporting channels.
  • Conducted digital safety outreach to 100+ community members on phishing, fraud, and social engineering awareness.

Verified Credentials

CyberOps Associate
Cisco
Apr 2024
FCSS Security Operations
Fortinet
Sep 2024
VMDR Specialist
Qualys
Mar 2025
Cybersecurity Professional
Google
Feb 2025
Security Awareness Specialist
Proofpoint
Jul 2025

Academic Background

M.Eng. Information Systems Security
Concordia University
2025 – 2026 GPA 3.5 Montreal, QC
B.Tech Information Technology
CHARUSAT University
2020 – 2024 CGPA 8.61 Gujarat, India

Get In Touch

Send a Message

Have a role or collaboration in mind? Drop me a line.

Direct Channels

Prefer a direct line? Use any of these.

LIVE SOC FEED
--:--:-- UTC
om@soc — interactive shell — type "help" ✕
om@soc:~$
[ ESC or click to exit the matrix ]
ACCESS GRANTED
WELCOME TO OM PATEL // SECURE PERIMETER
X:0000 Y:0000 · SCROLL:00% · T+00:00
SECTOR // HERO
[ TARGET LOCKED ]
GLOBAL THREAT MAP · ● LIVE · ATTACKS BLOCKED

SENTRY MODE

no operator input detected — perimeter watch engaged
monitoring… 00:00
move to re-authenticate
VISITOR THREAT ASSESSMENT ✕