┌──(soham㉿kali)-[~]
└─$ cat about_me.txt
Name : Soham Shah
Role : Threat Intelligence Engineer | SOC Analyst
Company : DNIF HYPERCLOUD (NetMonastery)
Focus : SIEM Ops · Detection Engineering · ML for Security
Mission : Turn raw telemetry into actionable threat intelligence
Email : sohamshahh@gmail.com
Location : Mumbai, India
Status : [ ONLINE ] — Building SentinelTI & hunting threats"Security is not a product, but a process." — Bruce Schneier
[*] Working on ............. SIEM ingestion across 100+ log sources @ DNIF HYPERCLOUD
[*] Building ............... SentinelTI — Multi-Tenant Threat Intelligence Platform
[*] Researching ............ Explainable ML (SHAP) for IOC risk scoring
[*] Studying ............... MITRE ATT&CK detection engineering · Splunk
[+] Education .............. MSc IT & Cybersecurity (CGPA 9.20)
[+] Ask me about .......... SIEM, Threat Intel, MITRE ATT&CK, Python, ML for security
| Project | What It Does | Stack | Status |
|---|---|---|---|
| 🛰️ SentinelTI | Multi-tenant Threat Intelligence Platform — 5+ IOC feeds, ML risk scoring, SHAP, MITRE mapping, SIEM push | FastAPI · MongoDB · Next.js · XGBoost | [ LIVE ] |
| 🎯 MITRE ATT&CK Incident Mapper | Connects to SIEMs and converts events into MITRE-mapped incident timelines + PDF reports | Flask · Next.js · TypeScript | [ LIVE ] |
| 📉 FP Tuning Dashboard | Detects recurring false-positive patterns, auto-suggests SOC tuning rules, quantifies time saved | Flask · Recharts · Next.js | [ LIVE ] |
| 📄 Resume | Full experience, projects & credentials | [PUBLIC] |
SentinelTI — Multi-Tenant Threat Intelligence Platform
------------------------------------------------------
+ 5-layer enrichment: GeoIP -> AbuseIPDB -> VirusTotal -> MITRE ATT&CK -> GreyNoise/URLhaus
+ Stacking ensemble (Random Forest + XGBoost + meta-learner) -> risk score 0-10
+ SHAP explainability: global feature importance + per-IP attribution
+ SIEM push connectors: Splunk HEC + Elasticsearch
+ Validated: 95% precision · 94% F1 · 4% FPR (5-fold CV)
Stack: FastAPI + MongoDB + JWT auth (backend) · Next.js 14 + TypeScript (frontend)+ [PUBLISHED] Understanding Cloud Outages and Security Breaches
Journal : IJRPR — Vol.5, Issue 11
Link : https://ijrpr.com/uploads/V5ISSUE11/IJRPR34989.pdf
Topics : Cloud Infrastructure, Security Incidents, Breach Analysis[✓] IBM AI Engineering ................ Coursera
[✓] AWS Cloud Fundamentals ............ Amazon Web Services
[✓] NIST Cybersecurity Framework ...... Risk Management
[✓] Cyber Threat Hunting .............. Active Countermeasures
[✓] SQL Intermediate .................. HackerRank
