PARAM-JASANI

NAME

Param Jasani

param-jasani — blue team operator, backend engineer and CTF author. 20, Mumbai.

Param's avatar: a cartoon dog in sunglasses and a green sweater typing on a laptop in front of falling green code
fig. 1: the operator

SYNOPSIS

param [--about] [--work] [--ctf] [--projects filter] [--writing] [--skills] [--hire]

DESCRIPTION

param is a 20-year-old Blue Team / Security Operations engineer and backend developer. I learn by building: a 19-node Kubernetes cluster on bare metal, a Splunk SOC fed by Sysmon and tested with MITRE Caldera, an IDS-to-SIEM pipeline on the ELK Stack, and an enterprise network with Active Directory, WSUS and WDS.

Before security I shipped backend code. At Hellbent Software I built REST APIs in Django, FastAPI and Flask and tuned Oracle queries. I still treat detection as an engineering problem: pipelines, data and automation.

These days I author SOC investigation scenarios and CTF challenges for HaxNation, write about threat intelligence, ICS/OT and the Mumbai security meetups, break AI models on Gray Swan Arena, and publish DFIR writeups for HTB Sherlocks and LetsDefend alerts.

EXAMPLES

A working shell. Try help, whoami, ls or sudo hire param.

guest@param:~$ whoami

param-jasani: blue team, backend, CTF author. type help.

ENVIRONMENT

AGE
20
LOCATION
Mumbai, India
ROLE
SOC scenario & CTF author @ HaxNation
STUDY
B.E. Computer Engineering, VCET Vasai (2024–27)
HANDLES
CVE · ZeroCVE · zero_cve
STATUS
open to SOC / blue team roles & internships
MOTTO
"Until death, all defeat is psychological."

EXIT STATUS

Returns 0 when things went well. Some results:
Top 1%TryHackMe. 0xE Guardian, 296 rooms, 47 badges.
14 SOCsEvery scenario on the HaxNation SOC Simulator: 321 alerts to triage.
19 nodesKubernetes homelab: 3 control planes, 15 workers, 7.5 TB Rook Ceph.
10+ postsMost prolific author on the HaxNation Blog.
DiamondGoogle Cloud Skills league. 14 badges incl. Google Security Operations.
5 starsHackerRank Python (gold). Java 3 stars.

HISTORY

  1. 2026-03 — now

    SOC Scenario & CTF Developer, HaxNation Mumbai

    • Authored all 14 scenarios on the HaxNation SOC Simulator (321 alerts). They are modelled on real campaigns: APT29, Kimsuky, RomCom, Emotet/QakBot, OceanLotus.
    • Design CTF challenges across web, Web3, network, crypto, forensics and infrastructure, mapped to MITRE ATT&CK.
    • Write for the HaxNation Blog (10+ posts) and added MDX, Mermaid, KaTeX and interactive React support to the platform.
  2. 2023-11 — 2024-03

    Backend Developer Intern, Hellbent Software

    • Built REST APIs with Django, FastAPI and Flask.
    • Optimised Oracle queries with indexing and PL/SQL; containerised services with Docker.
  3. 2024 — 2027

    B.E. Computer Engineering, VCET Vasai

    • CGPA 7.0
  4. 2021 — 2024

    Diploma in Computer Engineering, Govt. Polytechnic Nagpur

    • CGPA 9.2

CHALLENGES

I write the SOC investigation scenarios for the HaxNation CTF platform. Each one drops you into an alert queue rebuilt from a real campaign. You triage the noise, reconstruct the kill chain and answer the analyst questions.

soc-simulator/ 14 scenarios · 321 alerts · author: param

SOC scenarios by number of alerts
alertsvolumescenario
40RomCom: Unzipping Troubleweaponised RAR attachment → RomCom backdoor
35Operation Policy Review: the Kimsuky Breachthink-tank spear-phish, DPRK tradecraft
33Operation Cobalt KittyAPT32 / OceanLotus-style intrusion
32Winter's Bite: the Midnight Blizzard BreachAPT29 critical incident
27Silent Tidespear-phish → proxy C2 → staged exfil
26Operation Midnight Ciphercampaign against a regional bank
23Operation Azure EchoBITS jobs, containerised payload
21Silent Echofileless phish → creds → cloud exfil
21Flashback Forum BreachEmotet + QakBot cascade
21Operation Arctic Echopoisoned update → ransomware
14Operation Phantom ReceiptPayment_Receipt.exe infostealer
13Caught in the Web: KongTukemalicious redirect → obfuscated script
8Operation Ghost Scriptfileless Office-doc phish
7Operation Ghost Shellfileless RDP intrusion on a DMZ host

ctf/web3/ smart-contract exploitation

  • [#--]Sword Claimeasy
  • [##-]Ghost Stakermedium
  • [##-]Phantom Fundmedium
  • [###]Echo Vaulthard

PROJECTS

$ ls ~/projects

  • 2025-06

    k8s-homelab/

    A 19-node Kubernetes cluster built on bare metal: an HAProxy load balancer, 3 control planes, 15 workers, and Rook Ceph serving 7.5 TB raw. Evolved from a single control plane to an HA setup, and moved storage from Longhorn to Rook Ceph for transformer-training I/O. The build log documents each design decision.

    kubernetes haproxy rook-ceph longhorn ubuntu bash

  • 2025-06

    soc-lab/

    6 Windows endpoints shipping Sysmon telemetry into Splunk. I ran MITRE Caldera adversary emulation against it to prove the detections fired, then tuned them against real attack traces.

    splunk sysmon caldera att&ck windows

  • 2026-05

    qualys-vmdr-lab/

    Qualys Cloud Agents across Windows and Linux hosts. Findings prioritised with TruRisk and fed into a remediation workflow.

    qualys vmdr trurisk

  • 2025-03

    elk-siem-pipeline/

    Suricata IDS → Filebeat → Logstash → Elasticsearch → Kibana, with correlation rules for network threat detection.

    suricata filebeat logstash elasticsearch kibana

  • 2025-02

    enterprise-ad-lab/

    Active Directory, DHCP, DNS and VLANs, with WSUS for central patching and WDS for network OS deployment.

    active-directory wsus wds dns dhcp vlans

  • 2026

    mayajal-core/

    Māyājāl ("web of illusion"): an SSH honeypot in Rust. It fakes a Linux filesystem using per-user SQLite micro-DBs, emulates commands in tiers, and keeps HMAC-signed, encrypted session logs.

    rust ssh sqlite honeypot deception

  • 2026

    dispenser/

    Rust CLI for file forensics: recursive metadata, SHA-256 checksums, and sorting by extension or timestamp.

    rust cli sha-256

  • 2025

    libmagic-rs/

    Contributions to a pure-Rust rewrite of libmagic, the library behind the Unix file command.

    rust open-source file-formats

  • 2023-08

    secureroute/

    Java secure messenger: AES-CTR for messages, RSA for key exchange, MongoDB for storage.

    java aes-ctr rsa mongodb

  • 2023

    port-scanner/ · pcap-reader/ · cve-searcher/

    Early tools: a Java port and service scanner, a Python PCAP parser for traffic forensics, and offline search over the MITRE CVE database.

    java python pcap cve

More on github.com/param-jasani.

OPTIONS

--soc
Splunk, ELK Stack, Google SecOps, Sysmon, Suricata, Qualys VMDR, Wireshark, MITRE ATT&CK, MITRE Caldera, STIX/TAXII, DFIR
--infra
Kubernetes, Rook Ceph, HAProxy, Docker, Terraform, Active Directory, WSUS/WDS, Linux, networking
--lang
Rust, Python, Java, SQL / PL-SQL, Bash, PowerShell
--backend
Django, FastAPI, Flask, REST, Oracle, MongoDB, SQLite

FILES

SEE ALSO

AUTHOR

Written by Param Jasani. Send job offers, lab ideas and CTF feedback to:

<param_jasani@rediffmail.com>