- Building AI-powered tools that detect threats traditional security tools miss entirely
- 📄Research paper under review — Transformer-based Network Steganography Detection
A Transformer-Based Detector for Network Steganography with Improved Generalization
The Problem: Attackers hide malicious data inside normal DNS, ICMP, TCP, and UDP network traffic — a technique called Network Steganography. It is completely invisible to firewalls, IDS, and traditional deep learning detectors like CNN and LSTM, which collapse when exposed to techniques they haven't been trained on.
Our Solution: A Transformer-based detector that learns behavioral patterns in network flows rather than memorising tool signatures — enabling it to detect covert channels it has never seen before, with 94.42% accuracy under rigorous Leave-One-Technique-Out (LOTO) evaluation.
Impact: Outperforms LSTM by +16pp, CNN by +18pp, Random Forest by +24pp — all statistically significant (McNemar's test, p < 0.001)
📄 Manuscript under review for journal/conference publication, 2026
SOC Level 1 Analyst Path — TryHackMe (In Progress)
- Threat monitoring · Log analysis · Alert triage · Incident response · SIEM fundamentals
Home SOC Lab — Enterprise-Grade Setup
Built a full home SOC lab mirroring real enterprise architecture:
- VMs: Kali Linux · REMnux · Ubuntu DMZ · Ubuntu-Wazuh Server · Windows 10 · Windows Server 2022 · pfSense Firewall
- Network: Full subnetting · VLAN design · all traffic routed through pfSense
- Attacks simulated & detected: SSH/RDP brute force · Port scanning · SMB enumeration · SQL Injection · XSS · Privilege escalation · Malware simulation (EICAR) · PowerShell abuse
- Detection: All alerts triaged via Wazuh SIEM with full incident documentation
| Year | Milestone |
|---|---|
| 2025 | CTF competitions · TryHackMe labs · Network fundamentals |
| 2025 | Home SOC Lab built · Wazuh SIEM · Penetration testing course |
| 2025 | FYP begins — Transformer detector for Network Steganography |
| 2026 | SOC Internship · ML Internship · Research Assistant role |
| 2026 | Research paper written · Web app + Agentic AI analyst built |
| 2026 | NSCT Top 10% nationally · Paper under review · Graduating May 2026 |
- Network-Steganography — Transformer-based covert channel detector + Web App + Agentic AI Analyst (FYP)
- Home-SOC-lab — Full deployment documentation for a self-hosted SIEM using Wazuh, Sysmon, and open-source security tools.
- Open-Claw-Deployment — AI-powered SOC automation — OpenClaw AI agent orchestration.
- SOC-Lab-BruteForce-SSH — SSH brute force simulation · Wazuh SIEM detection · Incident report
- SOC-Network-Attacks-Lab — Nmap · SMB enumeration · Network attack detection
- Extensive-EDA — Data analysis & ML visualization pipeline
- Employee-Management — Full-stack web system · PHP · MySQL · HTML/CSS
Open to SOC Analyst · Security Researcher · Junior Penetration Tester roles.
Researching network security, AI-driven threat detection, or covert channels? Reach out.