Prathamesh Sangai
Cybersecurity Analyst — Malware Analysis · Digital Forensics · SOC Operations
Cybersecurity graduate with hands-on experience across threat detection, incident response, and secure system analysis — from reverse-engineering Android/Windows malware in a university research lab to building detection rules in a live SOC simulation. Based in Philadelphia, PA. Actively interviewing for full-time SOC / Cybersecurity Analyst roles.
About
I completed my M.S. in Cybersecurity at Drexel University (3.93 GPA) with a focus on malware analysis, digital forensics, cloud security, network defense, and cryptography. I currently work as a Research Assistant in Drexel's Security & Privacy Analytics Lab (SePAL), analyzing Android and Windows malware and building detection rules for real-world threat behavior.
Before Drexel, I worked as a Cybercrime Investigator in India, supporting law enforcement (CID Pune Police, DGGI) on fraud and identity-theft cases using forensic tools like Cellebrite, FTK Imager, and Magnet AXIOM. That mix — offensive curiosity plus forensic rigor — is what I bring to blue-team work now.
Outside of work, I build my own tools: an AI-assisted Android malware analysis sandbox, and a job-application tracker that parses my own inbox so nothing falls through the cracks during this search.
- locationPhiladelphia, PA
- degreeM.S. Cybersecurity, Drexel (3.93 GPA)
- focusThreat detection · IR · Malware analysis
- labSePAL — Drexel Security & Privacy Analytics Lab
- statusOpen to full-time roles
- languagesPython, C, C++, Java, Shell, SQL
Experience
- Providing IT support part-time while completing the transition into a full-time cybersecurity role.
- Analyzed Android and Windows malware to identify payload execution, persistence, and network exfiltration behavior.
- Built Frida hooks and Xposed modules to intercept sensitive API parameters and plaintext data prior to encryption.
- Inspected TLS and QUIC traffic to map telemetry endpoints, encryption workflows, and indicators of compromise.
- Developed YARA and Sigma rules to automate malware classification and behavioral detection in lab environments.
- Produced structured research summaries and maintained reproducible analysis notes to support ongoing lab workflows.
- Supported CID Pune Police and DGGI in fraud and identity-theft investigations involving mobile and computer evidence.
- Performed forensic imaging and artifact analysis using UFED, FTK Imager, Magnet Axiom, and Splunk.
- Correlated firewall, proxy, and application logs to validate suspicious activity and evidence timelines.
- Prepared chain-of-custody documentation and forensic reports suitable for legal proceedings.
Projects
- Building an evidence-based, AI-assisted platform for analyzing Android malware — combining automated sandboxing with AI-supported triage of behavior and evidence.
- A local, Gmail-based job-application tracker that reads confirmations, recruiter messages, assessments, interviews, rejections, and offers — and derives live application status automatically.
- Built around one rule: no job-related message is ever silently dropped. Every message links to an application, creates one, or lands in a review queue.
- Read-only Gmail OAuth throughout — no send or delete access, ever.
- Built a SOC lab using Splunk and Wazuh to generate alerts mapped to MITRE ATT&CK techniques and scenarios.
- Conducted log analysis and threat hunting to identify anomalous authentication and network behavior.
- Tuned detection rules to reduce false positives and improve alert fidelity across simulated incidents.
- Documented investigation workflows and incident response steps for repeatable SOC analysis and training.
- Performed OWASP Top-10 testing on DVWA and Juice Shop using Burp Suite, Nmap, and Metasploit.
- Identified XSS, SQL injection, and authentication flaws with proof-of-concept exploitation results.
- Documented vulnerability impact, severity levels, and remediation recommendations for developers.
- Produced professional penetration testing reports according to industry assessment standards.
- Developed an encrypted chat system using QUIC and TLS 1.3 with FastAPI-based authentication mechanisms.
- Implemented secure key exchange and session handling logic for low-latency, reliable communication.
- Analyzed protocol handshakes and packet flows to validate encryption integrity and session security guarantees.
- Evaluated transport-layer performance under unreliable and high-latency network conditions.
Skills
Programming
Blue Team
Red Team
Forensics
Cloud & Frameworks
Certifications
Contact
Open to full-time SOC Analyst, Cybersecurity Analyst, and Security Analyst roles — reach out directly, I respond fast.