Avinash Mathew
Varghese.
SOC Analyst & Security Consultant
I triage and investigate security alerts across Microsoft Sentinel, Google SecOps, and LogRhythm, and co-founded AMVAT Labs, a hands-on defensive security homelab.
Featured Projects
Hands-on work that doesn't fit on a resume.
SOC Utils
A self-hosted toolkit that replaces a stack of spreadsheets and shared docs with one Django app for SOC shift work — threat intel lookups, rostering, handover, health checks, and reporting.
- Django
- PostgreSQL
- Redis
- Docker Compose
- Threat Intelligence
- VirusTotal API
- AbuseIPDB API
AMVAT Labs
A hands-on homelab and documentation platform for both sides of security work: blue team network segmentation, SIEM/XDR, and IDS on the defensive side, plus red team web app pentesting and ethical hacking write-ups on the offensive side.
- Proxmox
- OPNsense
- Wazuh
- Suricata
- MITRE ATT&CK
- VLANs
- Blue Teaming
- Red Teaming
- Penetration Testing
- Ethical Hacking
Self-Hosted Stack
A home server running everything from password management to music streaming — all self-hosted, behind one reverse proxy and one login, so no third-party cloud gets to hold our data hostage.
- Docker Compose
- Traefik
- Authentik
- Vaultwarden
- Uptime Kuma
- VPN
- WAF
Snagr
Paste a link, and the track lands straight in the self-hosted music server's library — no download-then-drag-into-a-folder detour. Or send it straight to your device instead, if that's what you'd rather have.
- FastAPI
- yt-dlp
- WebSockets
- Docker
- ffmpeg
Skills
Security Operations & Monitoring
- SIEM (LogRhythm)
- SIEM (Google SecOps)
- SIEM (Microsoft Sentinel)
- SIEM (FortiSIEM)
- SIEM (Wazuh)
- SOAR (FortiSOAR)
- EDR/XDR (FortiXDR, Wazuh)
- Security Incident Response
- Threat Hunting
- Log Analysis
- Network Traffic Analysis
- Anomaly Detection
Network Security
- Firewalls (Sophos XG, OPNsense, PfSense)
- IDS/IPS (Suricata, CrowdSec)
- Network Segmentation (VLANs)
- VPN
- DNS Security (Pi-hole)
- Wireshark
Cloud Security
- AWS IAM
- AWS GuardDuty
- AWS KMS
- AWS CloudTrail
- AWS WAF
System Administration & Infrastructure
- Virtualization
- Docker
- Windows & Linux Systems Security
- Reverse Proxies
- ETL Processes
Programming & Automation
- Python
- Bash
- SQL
- Java
- Workflow Automation
- Playbook Development
Vulnerability Assessment & Penetration Testing
- Burp Suite
- Sqlmap
- John the Ripper
- Hydra
- Hashcat
- Nmap
Security Frameworks & Compliance
- ISO/IEC 27000
- ISO/IEC 38500
- ISO/IEC 31000
- Risk Assessment
- Policy Development
- Security Procedures
- Data Classification & Labelling