// SOC · Blue Team · Detection Engineering

Sarvesh Khanal

Entry-Level Cybersecurity Analyst | Transitioning from QA & Full-Stack Development

sarvesh@soc-lab: ~

~$ cat about.md

Computer Science graduate (BSc CSIT, Institute of Science and Technology, Tribhuvan University, 2022–2026), based in Kathmandu, Nepal.

Cybersecurity professional in training with hands-on lab experience in security monitoring, log analysis, and endpoint threat detection using SIEM tooling across Linux and Windows environments.

Background in software quality assurance and full-stack development (React.js, Node.js) gives a strong foundation in systems architecture, testing methodology, and analytical troubleshooting.

Currently pursuing a cybersecurity fundamentals course (security monitoring, threat analysis, SIEM operations) and actively building hands-on home labs.

Seeking an entry-level Cybersecurity Analyst / SOC Analyst internship or role.

~$ ls skills/

Security

  • SIEM (Wazuh)
  • Sysmon
  • File Integrity Monitoring
  • Threat Hunting
  • Log Analysis
  • Vulnerability Assessment
  • Incident Response Fundamentals
  • IAM Fundamentals

Systems & Networks

  • TCP/IP
  • DNS
  • HTTP/S
  • Linux (Ubuntu)
  • Windows
  • Active Directory Basics
  • Wireshark

Tools & Scripting

  • Wazuh
  • Sysmon
  • Nmap
  • Burp Suite
  • Postman
  • Selenium
  • Git
  • Python
  • Bash
  • SQL

Development (transferable background)

  • React.js
  • Node.js
  • JavaScript
  • Python
  • Django
  • SQL
  • RESTful APIs

~$ ls -la projects/

01

SIEM Home Lab — File Integrity Monitoring with Wazuh

Deployed a Wazuh Manager and Dashboard on Ubuntu 24.04 Server and registered a Windows 10 Wazuh Agent over TCP 1514. Configured real-time File Integrity Monitoring (FIM) in ossec.conf to detect file creation and deletion events on a monitored Windows directory, validated detection by triggering test alerts, and documented the architecture and configuration.

  • Wazuh
  • FIM
  • SIEM
  • Ubuntu
  • Windows
View on GitHub →
02

Threat Hunting with Wazuh SIEM and Sysmon

Built a two-tier lab with Wazuh Manager/Indexer/Dashboard on Ubuntu and a Wazuh Agent on Windows 11. Installed Sysmon (SwiftOnSecurity config) to capture process creation, PowerShell execution, and user-enumeration telemetry, forwarded it to Wazuh, simulated common Windows activity, and analyzed the resulting alerts in the dashboard.

  • Wazuh
  • Sysmon
  • SIEM
  • Threat Detection
  • Windows 11
View on GitHub →

~$ history --work

Web Developer — Brandworth Pvt Ltd

Nov 2025 – Feb 2026 · Kathmandu, Nepal

  • Built and integrated RESTful APIs with Node.js and SQL, developing a practical understanding of application, data, and infrastructure architecture.
  • Practiced systematic, detail-driven testing methodology using Selenium and Postman for functional and API testing — directly transferable to security analysis and vulnerability assessment.
  • Debugged React.js and Node.js code across the stack, reinforcing an analytical, root-cause mindset applicable to security investigation and log analysis.

~$ cat education.txt

Education

BSc in Computer Science and Information Technology (BSc CSIT)
Institute of Science and Technology (IOST), Tribhuvan University
Kathmandu, Nepal · 2022–2026

Certifications

  • API Testing Path (v12)
  • Python and Django
  • Learn Node.js
  • Namaste React

Currently pursuing: Cybersecurity Fundamentals course — security monitoring, threat analysis, SIEM operations.

~$ ./contact.sh

Get in touch

Send a message