Just a SOC analyst doing detection engineering across banking-sector SIEM environments (LogPoint, FortiSIEM, Wazuh), with a habit of digging past the alert to the mechanism underneath. I build automation to cut manual triage overhead and write custom detection rules for endpoint and network anomalies. Outside work: built a DNS resolver from scratch against RFC 1035, an ARP spoofing detector in C , design CTF challenges and I read Linux kernel source for fun. I write about what I find at prayush.hashnode.dev.