Skip to content
View rdx0120's full-sized avatar

Block or report rdx0120

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
rdx0120/README.md

Rohan Anand Dalvi

Security engineering · Detection & response · Security automation

Hi, I'm Rohan. I work in healthcare IT and security, where I spend much of my time on endpoint monitoring, Wazuh detections, and vulnerability remediation.

The projects here build on that work and give me room to explore areas like AWS, security automation, and application security. I include testing and debugging notes so you can see how things work, what went wrong, and what still needs work.

I'm looking for a dedicated security engineering role where I can keep building tools and improving detections. I'm also working toward a longer-term focus on application security.

Selected projects

Python · GitHub Actions · Semgrep · Terraform · OPA

I built this pipeline to check what security scanners actually examined before trusting their results. It blocks runs when scan coverage can't be established. In my AWS lab, I also applied a Terraform plan after it passed OPA checks, inspected the deployed IAM permissions, and tested GitHub Actions access through OIDC.

Code and setup · Design and debugging lessons

Sigma · Wazuh · Sysmon · MITRE ATT&CK

A collection of Windows and Google Workspace detections, with test fixtures and notes on investigating alerts. I validated two endpoint detections against live Wazuh telemetry. The deployment notes cover the troubleshooting along the way, including rules that loaded successfully but never fired.

Rules and setup · Wazuh deployment notes

Python · Greenbone · Nessus · CISA KEV · FIRST EPSS

This Python CLI helps decide which vulnerability findings to address first. It combines CISA KEV, EPSS scores, and asset context into a remediation queue with reasons and target dates. One detail I worked through was making sure a failed EPSS request could be retried instead of being saved as a missing score.

Code, usage, and methodology

CloudTrail · GuardDuty · Prowler · Sigma · Stratus Red Team

I used an isolated AWS account to fix configuration findings and test detections against six emulated attack techniques. My custom rules matched the captured CloudTrail events for all six. I documented the results, the delay before logs became searchable, and the gaps I observed during testing.

Lab walkthrough · Detection coverage and latency · Remediation notes

Other projects

  • YARAdec: My rebuild of the original YARA decompiler for YARA 4.x. This involved binary parsing, reconstructing rule logic, and comparing scan results before and after decompilation.
  • Threat Model Casebook: Practice threat models for payment systems and a multi-tenant API, covering what could go wrong, which mitigations matter most, and what risks remain.
  • Security Program Blueprint: A plan for running a small security program, informed by my healthcare work. It distinguishes controls I've operated from improvements I've proposed.

Currently learning

Outside these projects, I'm continuing to practice web application testing and secure code review.

Pinned Loading

  1. secure-pipeline secure-pipeline Public

    A security scanning pipeline that reports what each scanner actually examined, not just what it found. Fails on zero findings when coverage can't be proven.

    Python

  2. aws-detection-lab aws-detection-lab Public

    AWS security baseline with Prowler HIPAA audit, CloudTrail detections, and simulated attacks validating each rule.

    Python

  3. kev-epss-prioritizer kev-epss-prioritizer Public

    Vulnerability prioritization by CISA KEV, EPSS, and asset context instead of raw CVSS

    Python

  4. sigma-detection-pack sigma-detection-pack Public

    Sigma detection rules for Google Workspace and Windows endpoints — ATT&CK-mapped, CI-tested, with deployment runbooks

    Python

  5. YARAdec YARAdec Public

    Decompiles compiled YARA rules (.yarc) back to source — supports YARA 4.3–4.5.8

    Python 1