NAME
Param Jasani
param-jasani — blue team operator, backend engineer and CTF author. 20, Mumbai.
SYNOPSIS
DESCRIPTION
param is a 20-year-old Blue Team / Security Operations engineer and backend developer. I learn by building: a 19-node Kubernetes cluster on bare metal, a Splunk SOC fed by Sysmon and tested with MITRE Caldera, an IDS-to-SIEM pipeline on the ELK Stack, and an enterprise network with Active Directory, WSUS and WDS.
Before security I shipped backend code. At Hellbent Software I built REST APIs in Django, FastAPI and Flask and tuned Oracle queries. I still treat detection as an engineering problem: pipelines, data and automation.
These days I author SOC investigation scenarios and CTF challenges for HaxNation, write about threat intelligence, ICS/OT and the Mumbai security meetups, break AI models on Gray Swan Arena, and publish DFIR writeups for HTB Sherlocks and LetsDefend alerts.
EXAMPLES
A working shell. Try help, whoami, ls or sudo hire param.
guest@param:~$ whoami
param-jasani: blue team, backend, CTF author. type help.
ENVIRONMENT
- AGE
- 20
- LOCATION
- Mumbai, India
- ROLE
- SOC scenario & CTF author @ HaxNation
- STUDY
- B.E. Computer Engineering, VCET Vasai (2024–27)
- HANDLES
- CVE · ZeroCVE · zero_cve
- STATUS
- open to SOC / blue team roles & internships
- MOTTO
- "Until death, all defeat is psychological."
EXIT STATUS
| Top 1% | TryHackMe. 0xE Guardian, 296 rooms, 47 badges. |
|---|---|
| 14 SOCs | Every scenario on the HaxNation SOC Simulator: 321 alerts to triage. |
| 19 nodes | Kubernetes homelab: 3 control planes, 15 workers, 7.5 TB Rook Ceph. |
| 10+ posts | Most prolific author on the HaxNation Blog. |
| Diamond | Google Cloud Skills league. 14 badges incl. Google Security Operations. |
| 5 stars | HackerRank Python (gold). Java 3 stars. |
HISTORY
-
2026-03 — now
SOC Scenario & CTF Developer, HaxNation Mumbai
- Authored all 14 scenarios on the HaxNation SOC Simulator (321 alerts). They are modelled on real campaigns: APT29, Kimsuky, RomCom, Emotet/QakBot, OceanLotus.
- Design CTF challenges across web, Web3, network, crypto, forensics and infrastructure, mapped to MITRE ATT&CK.
- Write for the HaxNation Blog (10+ posts) and added MDX, Mermaid, KaTeX and interactive React support to the platform.
-
2023-11 — 2024-03
Backend Developer Intern, Hellbent Software
- Built REST APIs with Django, FastAPI and Flask.
- Optimised Oracle queries with indexing and PL/SQL; containerised services with Docker.
-
2024 — 2027
B.E. Computer Engineering, VCET Vasai
- CGPA 7.0
-
2021 — 2024
Diploma in Computer Engineering, Govt. Polytechnic Nagpur
- CGPA 9.2
CHALLENGES
I write the SOC investigation scenarios for the HaxNation CTF platform. Each one drops you into an alert queue rebuilt from a real campaign. You triage the noise, reconstruct the kill chain and answer the analyst questions.
soc-simulator/ 14 scenarios · 321 alerts · author: param
| alerts | volume | scenario |
|---|---|---|
| 40 | RomCom: Unzipping Troubleweaponised RAR attachment → RomCom backdoor | |
| 35 | Operation Policy Review: the Kimsuky Breachthink-tank spear-phish, DPRK tradecraft | |
| 33 | Operation Cobalt KittyAPT32 / OceanLotus-style intrusion | |
| 32 | Winter's Bite: the Midnight Blizzard BreachAPT29 critical incident | |
| 27 | Silent Tidespear-phish → proxy C2 → staged exfil | |
| 26 | Operation Midnight Ciphercampaign against a regional bank | |
| 23 | Operation Azure EchoBITS jobs, containerised payload | |
| 21 | Silent Echofileless phish → creds → cloud exfil | |
| 21 | Flashback Forum BreachEmotet + QakBot cascade | |
| 21 | Operation Arctic Echopoisoned update → ransomware | |
| 14 | Operation Phantom ReceiptPayment_Receipt.exe infostealer | |
| 13 | Caught in the Web: KongTukemalicious redirect → obfuscated script | |
| 8 | Operation Ghost Scriptfileless Office-doc phish | |
| 7 | Operation Ghost Shellfileless RDP intrusion on a DMZ host |
ctf/web3/ smart-contract exploitation
- [#--]Sword Claimeasy
- [##-]Ghost Stakermedium
- [##-]Phantom Fundmedium
- [###]Echo Vaulthard
PROJECTS
$ ls ~/projects
-
2025-06
k8s-homelab/
A 19-node Kubernetes cluster built on bare metal: an HAProxy load balancer, 3 control planes, 15 workers, and Rook Ceph serving 7.5 TB raw. Evolved from a single control plane to an HA setup, and moved storage from Longhorn to Rook Ceph for transformer-training I/O. The build log documents each design decision.
kubernetes haproxy rook-ceph longhorn ubuntu bash
-
2025-06
soc-lab/
6 Windows endpoints shipping Sysmon telemetry into Splunk. I ran MITRE Caldera adversary emulation against it to prove the detections fired, then tuned them against real attack traces.
splunk sysmon caldera att&ck windows
-
2026-05
qualys-vmdr-lab/
Qualys Cloud Agents across Windows and Linux hosts. Findings prioritised with TruRisk and fed into a remediation workflow.
qualys vmdr trurisk
-
2025-03
elk-siem-pipeline/
Suricata IDS → Filebeat → Logstash → Elasticsearch → Kibana, with correlation rules for network threat detection.
suricata filebeat logstash elasticsearch kibana
-
2025-02
enterprise-ad-lab/
Active Directory, DHCP, DNS and VLANs, with WSUS for central patching and WDS for network OS deployment.
active-directory wsus wds dns dhcp vlans
-
2026
mayajal-core/
Māyājāl ("web of illusion"): an SSH honeypot in Rust. It fakes a Linux filesystem using per-user SQLite micro-DBs, emulates commands in tiers, and keeps HMAC-signed, encrypted session logs.
rust ssh sqlite honeypot deception
-
2026
dispenser/
Rust CLI for file forensics: recursive metadata, SHA-256 checksums, and sorting by extension or timestamp.
rust cli sha-256
-
2025
libmagic-rs/
Contributions to a pure-Rust rewrite of libmagic, the library behind the Unix
filecommand.rust open-source file-formats
-
2023-08
secureroute/
Java secure messenger: AES-CTR for messages, RSA for key exchange, MongoDB for storage.
java aes-ctr rsa mongodb
-
2023
port-scanner/ · pcap-reader/ · cve-searcher/
Early tools: a Java port and service scanner, a Python PCAP parser for traffic forensics, and offline search over the MITRE CVE database.
java python pcap cve
More on github.com/param-jasani.
OPTIONS
- --soc
- Splunk, ELK Stack, Google SecOps, Sysmon, Suricata, Qualys VMDR, Wireshark, MITRE ATT&CK, MITRE Caldera, STIX/TAXII, DFIR
- --infra
- Kubernetes, Rook Ceph, HAProxy, Docker, Terraform, Active Directory, WSUS/WDS, Linux, networking
- --lang
- Rust, Python, Java, SQL / PL-SQL, Bash, PowerShell
- --backend
- Django, FastAPI, Flask, REST, Oracle, MongoDB, SQLite
FILES
haxnation.org/blog/
- HTB Mumbai Meetup #19: BYOVD, kernel drivers & EDR evasion
- How intelligently, intelligent people do threat intelligence?
- HTB Mumbai Meetup #18: Kubernetes security & physical pentesting
- HaxNation Mumbai Meetup: GRC, AI security & phishing
- Antisyphon Threat Hunting Summit 2026
- Breachforce Mumbai: container & Kubernetes security
- How we cleared VirusTotal false positives for our domain
- The Purdue Model
- HTB Mumbai Meetup #16: RADIUS, Kerberos & RCE
- Introduction to ICS/OT security
sec-writeups/
SEE ALSO
- security
- haxnation-ctf(1), tryhackme(1), hackthebox(1), htb-ctf(1), letsdefend(1), hackerone(1), grayswan-arena(1)
- writing
- haxnation-blog(5), sec-writeups(5)
- cloud
- google-cloud-skills(1), microsoft-learn(1)
- code
- github(1), leetcode(1), hackerrank(1), hackerearth(1)
AUTHOR
Written by Param Jasani. Send job offers, lab ideas and CTF feedback to: