{"$schema":"https://raw.githubusercontent.com/jsonresume/resume-schema/v1.0.0/schema.json","basics":{"name":"Sahil Anil Nikam","label":"SOC Analyst (L1) · VAPT · Blue Team","email":"sahilnikam133@gmail.com","phone":"+91 8329935878","url":"https://hackwithsahil.vercel.app","summary":"B.Tech Computer Science graduate (Sandip University, 2026, CGPA 8.53) working across SOC operations and offensive security. Three-month SOC Analyst internship at ESCOSS LLP deploying and administering Wazuh, implementing Splunk, and building integrations that centralised log collection across Windows and Linux endpoints. Certified across all five modules of the SevenMentors SOC Analyst Program — Networking, Linux, CEH, WAPT and Python for SOC. The work I care about is the loop: run a controlled red-team technique in an owned lab, map it to MITRE ATT&CK, then check whether the detection stack actually fired — and write the rule when it did not. Founder and security lead at Vrikaan, an AI threat-detection platform covering phishing and scam detection, real-time monitoring and dark-web exposure scanning. Recognised in \"The Cyber 50 — India's Elite Founders List\" by Indian Startup Times.","location":{"city":"Nashik","region":"Maharashtra","countryCode":"IN"},"profiles":[{"network":"GitHub","url":"https://github.com/sahilnikam2410","username":"sahilnikam2410"},{"network":"LinkedIn","url":"https://www.linkedin.com/in/sahilnikam-soc","username":"/in/sahilnikam-soc"},{"network":"YouTube","url":"https://www.youtube.com/@HackWithSahilYT","username":"@HackWithSahilYT"},{"network":"Vrikaan","url":"https://vrikaan.com","username":"vrikaan.com"}]},"work":[{"name":"ESCOSS LLP","position":"SOC Analyst Intern","startDate":"Mar–Jun 2026","summary":"Deployed and administered Wazuh, implemented Splunk, centralised logs across Windows and Linux endpoints. Monitored events, correlated logs, triaged alerts and ran incident response. Configured active response to auto-contain brute-force attempts. Certified by the COO and Director."},{"name":"Vrikaan","position":"Founder & Security Lead","startDate":"2024 – present","summary":"AI threat-detection platform: phishing and scam detection, real-time monitoring, dark-web exposure scanning. Named in \"The Cyber 50 — India's Elite Founders List\"."},{"name":"Academor","position":"Cyber Security Intern","startDate":"Aug–Sep 2023","summary":"Nmap scanning and reconnaissance; analysed phishing, DoS/DDoS and session-hijacking techniques defensively; cryptography and ethical-hacking labs on Kali Linux."}],"education":[{"institution":"Sandip University","studyType":"B.Tech CSE","area":"Computer Science & Engineering","startDate":"2022","endDate":"2026","score":"8.53 / 10","summary":"CGPA 8.53 / 10. Final-year work: The Silent Operator, a SOC detection and red-team simulation lab."}],"projects":[{"name":"The Silent Operator","description":"End-to-end SOC lab — Wazuh SIEM, Kali Linux, Windows 10, virtualised hosts — ingesting Sysmon and system logs from multiple endpoints into centralised dashboards. Controlled red-team attacks are executed against it, mapped to MITRE ATT&CK, then hunted from the defender side to find out what the stack missed.","keywords":["Wazuh","Sysmon","MITRE ATT&CK","Kali","Windows 10","Virtualised lab"],"highlights":["Simulated attacks mapped technique-by-technique to ATT&CK","Detected via log correlation, custom alert rules, triage and threat hunting","Exposed detection gaps, then closed them with new rules"],"url":"https://github.com/sahilnikam2410/silent-operator"},{"name":"Protocol Honeypot","description":"A network-based intrusion detection system and honeypot built to attract, capture and analyse real reconnaissance and unauthorised access attempts, profiling attacker behaviour into alerts an analyst can act on rather than raw noise.","keywords":["IDS","Honeypot","Log correlation","Linux"],"highlights":["Captures and logs unauthorised access and recon traffic","Correlates attacker behaviour into actionable alerts","Profiles technique patterns rather than single events"],"url":"https://github.com/sahilnikam2410/protocol-honeypot"},{"name":"Protocol Cinema","description":"Research into a steganographic command-and-control technique that tunnels data through public APIs. Studied in an authorised lab, then translated into detection logic for anomalous outbound channels and mapped to MITRE ATT&CK.","keywords":["Covert channels","Traffic analysis","Detection engineering","MITRE ATT&CK"],"highlights":["Analysed covert exfiltration over legitimate public APIs","Converted observed TTPs into detection logic","Lab-only — no live third-party infrastructure involved"],"url":"https://github.com/sahilnikam2410/protocol-cinema"},{"name":"Multi-Endpoint Monitoring Lab","description":"Multi-host virtualised lab (Windows 10, Kali Linux) with agent-based log forwarding from several endpoints into centralised dashboards — network configuration, host connectivity and full-fleet visibility, built from scratch and documented.","keywords":["Wazuh agents","Splunk","Virtualised lab","Centralised logging"],"highlights":["Endpoint agents deployed and configured across hosts","Simulated attack traffic analysed to find detection gaps","Dashboards built for network and system telemetry"],"url":"https://github.com/sahilnikam2410/monitoring-lab"},{"name":"Vrikaan — AI Threat Detection Platform","description":"Consumer-facing platform for phishing and scam detection, real-time monitoring and dark-web exposure scanning. Live phishing and social-engineering campaigns are analysed and converted into automated detection and classification logic.","keywords":["Threat detection","Phishing analysis","Serverless","Firebase","Production ops"],"highlights":["Found and fixed a quota bypass: the free-tier counter was a per-instance in-memory map, so on serverless it died at every cold start and a documented three-a-day limit was in practice unbounded — a caller only had to spread requests across instances. Counters moved into Firestore transactions","Quota scopes are hashed before storage, so enforcing a per-IP limit does not mean keeping a list of IPs","Payments verified server-side twice: a session, a webhook, then an independent confirmation, because a client claiming it paid is not evidence that it did","Secret boundary enforced by naming: anything VITE_ prefixed compiles into the browser and is treated as public, and the keys are not","Attacker techniques turned into classification logic, written back into language a non-specialist can act on","Scheduled backups and a runbook written for whoever is on call, not for its author"],"url":"https://github.com/sahilnikam2410/vrikaan"}],"skills":[{"name":"SOC & Blue Team","keywords":["Wazuh — deploy & administer","Splunk","Sysmon & Windows Event Logs","Log correlation","Alert triage","Incident response","Threat hunting","MITRE ATT&CK mapping","Active-response automation","Security configuration assessment","SOC reporting & escalation"]},{"name":"Offensive / VAPT","keywords":["Web app penetration testing","Vulnerability assessment","OWASP Top 10","SQL injection","Burp Suite","DVWA","Nmap recon & enumeration","Red-team attack simulation","Session-hijacking analysis","Structured vulnerability reporting"]},{"name":"Network, Systems & Code","keywords":["TCP/IP · DNS · DHCP · HTTP/S","CCNA fundamentals","Wireshark packet analysis","Firewalls & VPN concepts","Linux (Kali, Ubuntu) CLI","Windows 10 / Server admin","Virtualised multi-host labs","Endpoint agent deployment","System hardening","Python · Bash · C · C++ · Java"]}],"certificates":[{"name":"SOC Analyst Program — all 5 modules","issuer":"SevenMentors Pvt. Ltd.","date":"Networking · Linux · CEH · WAPT · Python"},{"name":"Cybersecurity Analyst Job Simulation","issuer":"TATA / Forage","date":"2024"},{"name":"Cybersecurity","issuer":"Tech Mahindra Foundation / Skill India","date":"2024"},{"name":"IT Security Foundations: Network Security","issuer":"LinkedIn Learning","date":"2025"},{"name":"Ethical Hacking: SQL Injection","issuer":"LinkedIn Learning","date":"2024"},{"name":"B.Tech Computer Science & Engineering","issuer":"Sandip University","date":"2022–2026 · CGPA 8.53"}],"meta":{"canonical":"https://hackwithsahil.vercel.app/resume.json","version":"v1","note":"Generated from the portfolio content. The role-targeted PDFs live under /resumes."}}