Prathamesh Sangai

Cybersecurity Analyst — Malware Analysis · Digital Forensics · SOC Operations

Cybersecurity graduate with hands-on experience across threat detection, incident response, and secure system analysis — from reverse-engineering Android/Windows malware in a university research lab to building detection rules in a live SOC simulation. Based in Philadelphia, PA. Actively interviewing for full-time SOC / Cybersecurity Analyst roles.

~/about $ cat profile.md

About

I completed my M.S. in Cybersecurity at Drexel University (3.93 GPA) with a focus on malware analysis, digital forensics, cloud security, network defense, and cryptography. I currently work as a Research Assistant in Drexel's Security & Privacy Analytics Lab (SePAL), analyzing Android and Windows malware and building detection rules for real-world threat behavior.

Before Drexel, I worked as a Cybercrime Investigator in India, supporting law enforcement (CID Pune Police, DGGI) on fraud and identity-theft cases using forensic tools like Cellebrite, FTK Imager, and Magnet AXIOM. That mix — offensive curiosity plus forensic rigor — is what I bring to blue-team work now.

Outside of work, I build my own tools: an AI-assisted Android malware analysis sandbox, and a job-application tracker that parses my own inbox so nothing falls through the cracks during this search.

M.S. in Cybersecurity — Drexel University
Philadelphia, PA · Dec 2025 · GPA 3.93
Focus: Malware Analysis, Digital Forensics, Cloud Security, Network Defense, Cryptography
B.Tech in Information Technology — VIIT
Pune, India · Aug 2019 – Jun 2023
  • locationPhiladelphia, PA
  • degreeM.S. Cybersecurity, Drexel (3.93 GPA)
  • focusThreat detection · IR · Malware analysis
  • labSePAL — Drexel Security & Privacy Analytics Lab
  • statusOpen to full-time roles
  • languagesPython, C, C++, Java, Shell, SQL
~/experience $ tail -f career.log

Experience

Aug 2026 — Present
IT Support Analyst current
Jazz Wireless LLC · Philadelphia, PA (Part-time)
  • Providing IT support part-time while completing the transition into a full-time cybersecurity role.
Jan 2025 — Present
Research Assistant — Cybersecurity & Malware Analysis current
Drexel University — Security & Privacy Analytics Lab (SePAL) · Philadelphia, PA
  • Analyzed Android and Windows malware to identify payload execution, persistence, and network exfiltration behavior.
  • Built Frida hooks and Xposed modules to intercept sensitive API parameters and plaintext data prior to encryption.
  • Inspected TLS and QUIC traffic to map telemetry endpoints, encryption workflows, and indicators of compromise.
  • Developed YARA and Sigma rules to automate malware classification and behavioral detection in lab environments.
  • Produced structured research summaries and maintained reproducible analysis notes to support ongoing lab workflows.
Aug 2022 — Nov 2023
Cybercrime Investigator Intern
Sana Cyber Forensics · Maharashtra, India
  • Supported CID Pune Police and DGGI in fraud and identity-theft investigations involving mobile and computer evidence.
  • Performed forensic imaging and artifact analysis using UFED, FTK Imager, Magnet Axiom, and Splunk.
  • Correlated firewall, proxy, and application logs to validate suspicious activity and evidence timelines.
  • Prepared chain-of-custody documentation and forensic reports suitable for legal proceedings.
~/projects $ ls -la ./case-files

Projects

CASE_ID: PS-2026-01 ACTIVE
AndroAI Sandbox
Jun 2026 — Present
  • Building an evidence-based, AI-assisted platform for analyzing Android malware — combining automated sandboxing with AI-supported triage of behavior and evidence.
PythonFastAPIADBAndroid EmulatorPytest
CASE_ID: PS-2026-02 ACTIVE
JobTrace
2026
  • A local, Gmail-based job-application tracker that reads confirmations, recruiter messages, assessments, interviews, rejections, and offers — and derives live application status automatically.
  • Built around one rule: no job-related message is ever silently dropped. Every message links to an application, creates one, or lands in a review queue.
  • Read-only Gmail OAuth throughout — no send or delete access, ever.
PythonFastAPISQLiteGmail API
CASE_ID: PS-2025-03 COMPLETED
SOC Incident Simulation Lab
2025
  • Built a SOC lab using Splunk and Wazuh to generate alerts mapped to MITRE ATT&CK techniques and scenarios.
  • Conducted log analysis and threat hunting to identify anomalous authentication and network behavior.
  • Tuned detection rules to reduce false positives and improve alert fidelity across simulated incidents.
  • Documented investigation workflows and incident response steps for repeatable SOC analysis and training.
SplunkWazuhMITRE ATT&CK
CASE_ID: PS-2024-04 COMPLETED
Web Application Penetration Testing Lab
2024
  • Performed OWASP Top-10 testing on DVWA and Juice Shop using Burp Suite, Nmap, and Metasploit.
  • Identified XSS, SQL injection, and authentication flaws with proof-of-concept exploitation results.
  • Documented vulnerability impact, severity levels, and remediation recommendations for developers.
  • Produced professional penetration testing reports according to industry assessment standards.
Burp SuiteNmapMetasploitOWASP Top-10
CASE_ID: PS-2024-05 COMPLETED
QUIC Secure Chat Application
Apr 2024 — Jun 2024
  • Developed an encrypted chat system using QUIC and TLS 1.3 with FastAPI-based authentication mechanisms.
  • Implemented secure key exchange and session handling logic for low-latency, reliable communication.
  • Analyzed protocol handshakes and packet flows to validate encryption integrity and session security guarantees.
  • Evaluated transport-layer performance under unreliable and high-latency network conditions.
QUICTLS 1.3FastAPI
~/skills $ cat loadout.yaml

Skills

Programming

PythonCC++JavaShellSQLHTMLCSS

Blue Team

SplunkELKWazuhWiresharkSysmonOSQueryCrowdStrike Falcon

Red Team

NmapMetasploitBurp SuiteOWASP ZAPNessusNikto

Forensics

CellebriteFTK ImagerMagnet AXIOMAutopsyChain of Custody

Cloud & Frameworks

AWS IAMAWS EC2AWS S3CloudTrailDockerMITRE ATT&CKNIST CSFOWASP Top-10
~/certifications $ cat credentials.log

Certifications

Ethical Hacking Essentials (EHE)
EC-Council
✓ EARNED
Digital Forensics Essentials (DFE)
EC-Council
✓ EARNED
Introduction to Cybersecurity
Cisco
✓ EARNED
Career Essentials in Cybersecurity
Microsoft & LinkedIn
✓ EARNED
Security+
CompTIA
IN PROGRESS
~/contact $ ./reach_out.sh

Contact

Open to full-time SOC Analyst, Cybersecurity Analyst, and Security Analyst roles — reach out directly, I respond fast.