Binod Rawat

Binod Rawat

Cybersecurity Analyst & Threat Hunter

Specialization:Defensive Security & Threat Hunting

Namaste 🙏🏼!
My name is Binod Rawat
I work as a

Specialized in SOC Operations, Threat Hunting, Detection Engineering, and Incident Response. I map adversary TTPs to the MITRE ATT&CK framework, craft custom Sigma & YARA rules, and build resilient defensive telemetry systems.

SOC Operations (Tier 1-3)
Sigma & YARA Rule Authoring
Wazuh SIEM & CrowdStrike
Memory & Host Forensics
500+
Alerts Triaged & Investigated
Multi-stage SOC alerts analyzed across SIEM and EDR platforms.
20+
Custom Detection Rules
Crowdsrike correlation rules authored using CQL and deployed into production SIEM.
99.8%
Incident SLA Compliance
Consistently meeting P1/P2 incident detection & response SLAs.
40+
Threat Hunts Conducted
Proactive hypothesis-driven hunts based on MITRE ATT&CK TTPs.
Core Expertise

Featured Security Capabilities

View All Skills

Threat Hunting

Hypothesis-driven threat hunting targeting persistence, privilege escalation, and lateral movement.

Verified Competency

Detection Engineering

Designing, testing, and tuning high-fidelity detection rules mapped to MITRE ATT&CK.

Verified Competency

Incident Response

End-to-end incident handling, root-cause analysis, containment, and eradication playbooks.

Verified Competency

MITRE ATT&CK Framework

Mapping adversary TTPs, gap analysis, and defense validation across enterprise matrix.

Verified Competency

Wazuh SIEM

Architecting open-source XDR/SIEM, agent deployment, XML rule tuning, and decoder writing.

Verified Competency

CrowdStrike Falcon

EDR telemetry monitoring, custom IOA creation, real-time response (RTR), and host isolation.

Verified Competency
Validated Knowledge

Industry Credentials

All Certifications
CR

Falcon Administrator

CrowdStrike University2026-05

LP33487
CR

Incident Responder

CrowdStrike University2026-07

LP37163
CR

Threat Hunter

CrowdStrike University2026-06

LP35548
Knowledge Sharing

Recent Technical Articles

Read Blog
Detection Engineering7 min read

Building Production-Grade Wazuh Detection Rules for Ransomware Behaviors

A deep dive into writing custom XML rules and decoders in Wazuh to detect shadow copy deletion, process injection, and vssadmin abuse in real time.

Read Technical Case Study
Threat Hunting10 min read

Proactive Threat Hunting using MITRE ATT&CK & Process Lineage Analysis

Learn how to hunt for stealthy persistence and privilege escalation by inspecting parent-child process anomalies in Microsoft Sysmon and EDR logs.

Read Technical Case Study