Tanisha Brahma
SOC analyst · Detection engineering · Applied cryptography
- 06 Years in security
- 11 Credited CVEs
- 23 Incidents led
- 912 Detections shipped
Experience
Independent Practice
Jul 2024 — PresentDetection Engineering & Applied Cryptography
- Rebuilt a tier-1 payments processor's SOC ruleset as version-controlled Sigma — 912 rules migrated, false positives down 68% without losing a single true positive.
- Led incident response for a supply-chain signing-key compromise: containment in 3h 14m, 2,481 artefacts revoked, zero downstream impact.
- Shipped a hybrid X25519 + ML-KEM-768 handshake across 4,900 payment endpoints with 1.8ms mean overhead and zero downtime.
- Maintain Cryptkit, an open-source constant-time primitives library — 41k downloads a month, 23 contributors, timing tests that fail the build in CI.
Enterprise SOC
2020 — Jul 2024Tier-2 Analyst → Detection Lead
- Started on a tier-two console triaging endpoint alerts; moved into detection engineering when it became clear the rules were the product, not the console.
- Led 23 incidents from first alert through post-mortem — containment first, attribution last, and a write-up that names the control that failed.
- Learned cryptography by necessity: half the incidents traced back to a primitive used wrongly — a nonce reused, a key stored beside its data, a comparison that leaked timing.
Skills
- Detection & response
- Sigma, Splunk ES / SPL, MITRE ATT&CK, Detection-as-code, Telemetry pipelines, Incident response, Threat hunting, Post-mortems
- Cryptography
- X25519, ML-KEM-768, AEAD constructions, Noise protocol, Constant-time code, Lattice attacks, liboqs, BoringSSL, dudect
- Languages & tooling
- Rust, Python, Go (reading), ProVerif, Git / GitHub, HSM integration, CI/CD, PGP · Ed25519, criterion, 90-day disclosure
Certifications
- OSCP — Offensive Security Certified Professional (2021)
- GXPN — GIAC Exploit Researcher and Advanced Penetration Tester (2023)
- CISSP — Certified Information Systems Security Professional (2024)
- CKS — Certified Kubernetes Security Specialist (2025)
CVE credits
- CVE-2025-41802 — Session inheritance across resumption in a TLS terminator (CVSS 8.6)
- CVE-2024-33917 — Certificate chain validation bypass on renegotiation (CVSS 7.4)
- CVE-2024-28450 — Nonce reuse in an AEAD wrapper under key rotation (CVSS 6.8)
- CVE-2023-51166 — Timing disclosure in ECDSA scalar multiplication (CVSS 5.9)
Talks & papers
- Nullcon Goa — Detections are a codebase, not a console (2026)
- Real World Crypto — Shipping hybrid post-quantum without a flag day (2026)
- BSides Bangalore — Nine hours: anatomy of a signing key compromise (2025)
- IACR ePrint — A symbolic model for identity-hiding Noise variants (2024)