Tanisha Brahma

SOC analyst · Detection engineering · Applied cryptography

  • 06 Years in security
  • 11 Credited CVEs
  • 23 Incidents led
  • 912 Detections shipped

Experience

Independent Practice

Jul 2024 — Present

Detection Engineering & Applied Cryptography

  • Rebuilt a tier-1 payments processor's SOC ruleset as version-controlled Sigma — 912 rules migrated, false positives down 68% without losing a single true positive.
  • Led incident response for a supply-chain signing-key compromise: containment in 3h 14m, 2,481 artefacts revoked, zero downstream impact.
  • Shipped a hybrid X25519 + ML-KEM-768 handshake across 4,900 payment endpoints with 1.8ms mean overhead and zero downtime.
  • Maintain Cryptkit, an open-source constant-time primitives library — 41k downloads a month, 23 contributors, timing tests that fail the build in CI.

Sigma · Rust · Python · Splunk ES · liboqs · ProVerif

Enterprise SOC

2020 — Jul 2024

Tier-2 Analyst → Detection Lead

  • Started on a tier-two console triaging endpoint alerts; moved into detection engineering when it became clear the rules were the product, not the console.
  • Led 23 incidents from first alert through post-mortem — containment first, attribution last, and a write-up that names the control that failed.
  • Learned cryptography by necessity: half the incidents traced back to a primitive used wrongly — a nonce reused, a key stored beside its data, a comparison that leaked timing.

Splunk ES · Sigma · Python · MITRE ATT&CK

Skills

Detection & response
Sigma, Splunk ES / SPL, MITRE ATT&CK, Detection-as-code, Telemetry pipelines, Incident response, Threat hunting, Post-mortems
Cryptography
X25519, ML-KEM-768, AEAD constructions, Noise protocol, Constant-time code, Lattice attacks, liboqs, BoringSSL, dudect
Languages & tooling
Rust, Python, Go (reading), ProVerif, Git / GitHub, HSM integration, CI/CD, PGP · Ed25519, criterion, 90-day disclosure

Certifications

  • OSCP — Offensive Security Certified Professional (2021)
  • GXPN — GIAC Exploit Researcher and Advanced Penetration Tester (2023)
  • CISSP — Certified Information Systems Security Professional (2024)
  • CKS — Certified Kubernetes Security Specialist (2025)

CVE credits

  • CVE-2025-41802 — Session inheritance across resumption in a TLS terminator (CVSS 8.6)
  • CVE-2024-33917 — Certificate chain validation bypass on renegotiation (CVSS 7.4)
  • CVE-2024-28450 — Nonce reuse in an AEAD wrapper under key rotation (CVSS 6.8)
  • CVE-2023-51166 — Timing disclosure in ECDSA scalar multiplication (CVSS 5.9)

Talks & papers

  • Nullcon Goa — Detections are a codebase, not a console (2026)
  • Real World Crypto — Shipping hybrid post-quantum without a flag day (2026)
  • BSides Bangalore — Nine hours: anatomy of a signing key compromise (2025)
  • IACR ePrint — A symbolic model for identity-hiding Noise variants (2024)