Four case studies: detection engineering, incident response, post-quantum migration and a custodial wallet audit.
Sentinel Grid
Detection-as-code for a 40,000 EPS estate: 912 hand-edited correlation rules rebuilt as version-controlled Sigma, every change gated behind telemetry-backed unit tests, alert queue cut by two thirds without losing a true positive.
SigmaPythonSplunk ESCI
001
Blackout
Nine hours from first alert to eradication. A build server started signing artefacts it had not built — a stolen signing key used from another network. The timeline of that night and what it changed.
Incident responseCode signingHSMForensics
002
Lattice
Hybrid X25519 + ML-KEM across a payments fabric — post-quantum key exchange with no flag day. Both schemes ran in parallel for two quarters, and every millisecond of the cost was measured.
RustliboqsBoringSSLML-KEM-768
003
Redline
Breaking a custodial wallet before someone else did: a four-week assessment that recovered a signing key from a memory dump, then again from a timing side channel — and the remediation written with the team that fixed it.
Key managementECDSATiming analysisHSM
004
03
About
SOC analyst turned detection lead, now independent, writing production cryptography from Durgapur.
// Brief@Junecoderr
I catch intrusions for a living and write the cryptography that makes them expensive. Somewhere between a noisy alert queue and too much curiosity, good detections tend to happen.
06Years in security
11Credited CVEs
23Incidents led
912Detections shipped
┌┐└┘Tanisha Brahma
04
Experience
Six years across an enterprise SOC and independent practice.
Rebuilt a tier-1 payments processor's SOC ruleset as version-controlled Sigma — 912 rules migrated, false positives down 68% without losing a single true positive.
Led incident response for a supply-chain signing-key compromise: containment in 3h 14m, 2,481 artefacts revoked, zero downstream impact.
Shipped a hybrid X25519 + ML-KEM-768 handshake across 4,900 payment endpoints with 1.8ms mean overhead and zero downtime.
Maintain Cryptkit, an open-source constant-time primitives library — 41k downloads a month, 23 contributors, timing tests that fail the build in CI.
SigmaRustPythonSplunk ESliboqsProVerif
2020
Enterprise SOC
Tier-2 Analyst → Detection Lead
2020 — Jul 2024
Started on a tier-two console triaging endpoint alerts; moved into detection engineering when it became clear the rules were the product, not the console.
Led 23 incidents from first alert through post-mortem — containment first, attribution last, and a write-up that names the control that failed.
Learned cryptography by necessity: half the incidents traced back to a primitive used wrongly — a nonce reused, a key stored beside its data, a comparison that leaked timing.
Splunk ESSigmaPythonMITRE ATT&CK
Now
05
Recognition
Certifications, credited CVEs, talks and papers.
Certifications
OSCPOffensive Security Certified Professional2021
GXPNGIAC Exploit Researcher and Advanced Penetration Tester2023
CISSPCertified Information Systems Security Professional2024
CKSCertified Kubernetes Security Specialist2025
CVE credits
CVE-2025-41802Session inheritance across resumption in a TLS terminatorCVSS 8.6
CVE-2024-33917Certificate chain validation bypass on renegotiationCVSS 7.4
CVE-2024-28450Nonce reuse in an AEAD wrapper under key rotationCVSS 6.8
CVE-2023-51166Timing disclosure in ECDSA scalar multiplicationCVSS 5.9
Talks & papers
Nullcon GoaDetections are a codebase, not a console2026
Real World CryptoShipping hybrid post-quantum without a flag day2026
BSides BangaloreNine hours: anatomy of a signing key compromise2025
IACR ePrintA symbolic model for identity-hiding Noise variants2024