About Binod Rawat
A passionate defensive security practitioner focused on SOC operations, threat intelligence integration, and continuous security telemetry optimization.
Cybersecurity Journey & Approach
My security journey began with a deep fascination for operating system internals and network traffic analysis. Over the past several years, I have evolved from analyzing basic firewall logs into designing end-to-end security telemetry pipelines for enterprise enterprise SOC operations.
I believe modern defensive security (Blue Team) requires a proactive mindset—hunting for threat indicators long before alerts escalate. By leveraging automation, MITRE ATT&CK mapping, and open-source SIEM technologies like Wazuh, I strive to minimize mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR).
Career Objectives
- Advance threat hunting methodologies to catch zero-day living-off-the-land techniques.
- Develop automated SOAR playbooks for seamless containment of host & cloud endpoints.
- Build interactive security dashboards using CQL (CrowdStrike Query Language) for real-time threat visibility and incident response.
Experience & Education
Interactive milestone history
SOC Analyst
• Raechal Enterprises Pvt. Ltd. • Kathmandu, Nepal
- •Performed continuous security monitoring, alert triage, incident investigation, and log analysis using Falcon NG-SIEM.
- •Conducted proactive threat hunting to identify Indicators of Compromise (IOCs), suspicious activities, and anomalous behavior across enterprise environments.
- •Developed and optimized CQL queries to improve threat detection, investigation efficiency, and SOC visibility.
- •Configured centralized log ingestion from Windows, Ubuntu, Linux servers, and pfSense firewall devices into Falcon NG-SIEM.
- •Designed SIEM dashboards for improved visibility, security monitoring, and operational efficiency.
- •Developed correlation rules and detection logic to improve alert accuracy and significantly reduce false positives.
- •Investigated phishing attacks, malware detections, brute-force attempts, privilege escalation events, and authentication anomalies following incident response procedures.
- •Prepared technical threat reports documenting investigations, attack timelines, root cause analysis, and mitigation recommendations.
- •Created SOC investigation workflows to standardize incident analysis and improve analyst response time.
- •Worked closely with security teams to validate incidents, enhance detection capabilities, and continuously improve SOC operations.