Portrait of Tomesh Kumar Sahu

Hi, I'm

Tomesh Kumar Sahu

Cybersecurity Engineer Penetration Tester CEH

I specialise in threat detection & response

I detect, investigate and contain threats, harden the environments attackers target, and test defences the way an attacker would. Five-plus years across security operations, engineering and offensive security.

tomesh@secxshield — zsh monitoring
  • 5+years in cybersecurity
  • 100+SIEM & SOAR use cases built
  • 20+security platforms worked with
  • CEHCertified Ethical Hacker

Defender by trade, attacker by method

I started in security operations, triaging alerts and learning what attackers actually do. Today my core work is threat detection and incident response: spotting what's wrong, investigating it, containing it and making sure it can't happen the same way twice.

Around that core I build the systems that make detection work, with 100+ SIEM and SOAR use cases, EDR, XDR and MDR rollouts across several platforms, and hardened endpoints, email and identity. I also analyse malware and run investigations end to end.

On the offensive side I'm a penetration tester and bug bounty hunter. I run red team simulations and tool POCs, which means I test defences the way an attacker would, then help fix what I find. I also train schools, colleges and institutions on staying safe from cyber crime.

Current role
Senior Implementation Specialist (Security SME)
Experience
5+ years in cybersecurity
Credential
Certified Ethical Hacker (CEH)
Available for
Freelance projects, training engagements and full-time roles
Off the clock
Linux by choice, electronics and hardware tinkering, gadgets, nature and long drives

What I do

Eight areas, in order of how much of my time they take.

Threat detection & response

Monitoring, alert triage and mitigation across endpoint, network, email and identity.

Incident response & investigation

Scoping, containment, root cause, malware analysis, forensics and recovery support.

Penetration testing & red teaming

Authorised web and infrastructure testing, attack simulations and tool POCs.

SIEM & SOAR engineering

100+ detection and automation use cases, log onboarding, dashboards and playbooks.

Endpoint security & hardening

EDR, XDR and MDR across platforms, secure baselines, patching and exposure reduction.

Email, identity & cloud

Microsoft 365, Entra ID, BEC controls, SPF, DKIM, DMARC and sign-in investigations.

Vulnerability management

Assessment, validation, prioritisation, remediation tracking and retesting.

Threat intelligence & OSINT

Reputation analysis, reconnaissance, dark web monitoring and fraud attribution.

Featured work

How the work fits together. Every diagram is live: hover or tap a component to see what it does. Client details are deliberately left out.

detection-response / lifecycleHover or tap a component

Detection and investigation run across the top; containment and recovery come back along the bottom.

Core workDay to day

Threat detection & incident response

Across multiple EDR, XDR and MDR platforms

My core duty: watching security telemetry, triaging alerts, investigating what is real, and containing threats before they spread. I work across several EDR, XDR and MDR platforms, so the method matters more than any single tool.

  • Alert triage and investigation across endpoint, SIEM, email and identity telemetry.
  • Containment through endpoint isolation, account lockdown, quarantine and blocking indicators.
  • Post-incident hardening and detection tuning, so the same attack fails next time.
  • SentinelOne
  • Field Effect
  • Huntress
  • Trend Micro Worry-Free
  • Perch SIEM
  • Microsoft 365
siem-soar / detection-engineeringHover or tap a component

Detection is built across the top; automation and response come back along the bottom.

Detection engineeringBuilt at scale

SIEM & SOAR engineering

100+ detection and automation use cases

Building the detection layer itself: onboarding log sources, writing correlation searches and use cases, and automating repetitive investigation with SOAR playbooks. One example is a playbook that catches suspicious VPN logins, deduplicates the source IPs and enriches them with threat intelligence before deciding whether to alert.

  • 100+ SIEM and SOAR use cases across detection, enrichment and response.
  • Dashboards and reporting that give security teams a clear operational picture.
  • Playbooks that remove repetitive analyst work while keeping a human in the loop.
  • Splunk ES
  • Splunk SOAR
  • SPL
  • Splunk ITSI
  • Perch SIEM
  • VirusTotal
offensive / pentest-redteamHover or tap a component

The attack runs across the top; detection checks and the report come back along the bottom.

Offensive securityAuthorised testing

Penetration testing & red teaming

Web, infrastructure and autonomous testing

Authorised penetration testing of web applications and infrastructure, plus red team simulations that check whether defences catch a real attacker. Because I also work on the defensive side, every finding comes with practical remediation and a detection to match.

  • Web application, WordPress and infrastructure testing, plus external attack-surface assessment.
  • Autonomous penetration testing to map realistic attack paths at scale.
  • Red team simulations and tool POCs that validate EDR and SIEM coverage.
  • Kali Linux
  • Nuclei
  • Nikto
  • WPScan
  • Horizon3.ai NodeZero
  • Vonahi
  • Qualys
endpoint-security / hardeningHover or tap a component

Rollout runs across the top; ongoing protection loops back along the bottom.

Endpoint securityMulti-platform

Endpoint security & hardening

Rollouts, migrations and secure baselines

Securing endpoints across platforms: deploying and migrating EDR, XDR and MDR solutions, designing policies and exclusions, and hardening servers and workstations so attackers have less to work with.

  • Migrations from legacy antivirus to modern EDR across Windows and Linux.
  • Agent health, troubleshooting and narrowly scoped exclusions.
  • Hardening baselines, patch management and public-exposure reduction.
  • SentinelOne
  • Field Effect
  • Huntress
  • Trend Micro
  • Qualys patching
  • ScreenConnect

More of what I work on

Malware analysis & forensics

Analysing suspicious files and behaviour, extracting indicators of compromise, and endpoint forensics to reconstruct what happened.

  • VirusTotal
  • AbuseIPDB
  • IOC extraction
  • Process analysis

Email & identity security

Mail-flow protection, BEC controls, quarantine and message trace, plus sign-in, MFA and mailbox-rule investigations.

  • Trend Micro Email Security
  • Proofpoint
  • Hornetsecurity
  • Exchange Online
  • Entra ID
  • DMARC

Vulnerability management

Internal and external assessment, validation, risk-based prioritisation, remediation tracking and retesting.

  • Qualys VMDR
  • NodeZero
  • Vonahi
  • Nuclei
  • TLS/SSL

Secure access

Zscaler deployment and policy for secure internet and private access, with logs streamed into the SIEM.

  • Zscaler ZIA
  • Zscaler ZPA
  • Client Connector
  • NSS

Security awareness

Phishing simulation campaigns, targeted training for users who fail, and reporting on results.

  • KnowBe4
  • BullPhish ID
  • Phishing simulation

Dark web monitoring

Watching for leaked credentials and exposed data, and acting on them before they are used.

  • Dark Web ID
  • Dehashed
  • Credential exposure

Security tool POCs

Hands-on evaluations before rollout: does it detect, does it scale, does it fit the environment?

  • EDR / XDR
  • SIEM
  • SOAR
  • VAPT tools

OSINT & cybercrime investigation

Open-source intelligence for attribution, reconnaissance and fraud investigations.

  • SpiderFoot
  • Amass
  • Recon-ng
  • theHarvester
  • Sherlock

Bug bounty hunting

Finding and responsibly reporting vulnerabilities in public bug bounty programs.

  • Web testing
  • Recon
  • Responsible disclosure

Case files

Real investigations, rewritten so nothing identifies a client, a person or a system. Open a file to see how it was handled.

Incident response Ransomware-related server incident Unauthorised remote access led to ransomware activity on a server.
  1. Correlated endpoint telemetry with authentication events to trace how access was gained.
  2. Supported containment of the affected system and the account involved.
  3. Supported recovery coordination with the wider team.
  4. Recommended control improvements around MFA, endpoint protection coverage and remote access.

Outcome Containment and recovery supported, with clear recommendations to close the remote-access gap.

Identity & email Microsoft 365 account compromise A suspicious sign-in alert, followed from first signal to lessons learned.
  1. AlertRisky or unlikely-location sign-in raised.
  2. TriageWas the activity explainable by the user?
  3. TelemetrySign-in logs, MFA results, IP reputation.
  4. Message traceWhat was sent or received during the window.
  5. Identity analysisSessions, devices, MFA changes.
  6. CorrelationEndpoint and SIEM events for the same user.
  7. ContainmentPassword reset, sessions revoked, MFA enforced.
  8. RemediationMalicious inbox and forwarding rules removed.
  9. LessonsControls and detections improved.
Detection engineering When AI coding tools look like malware EDR flagged legitimate developer and AI assistant activity as suspicious.

AI coding assistants and CLI tools spawn PowerShell and Bash, write scripts and execute them: behaviour that closely resembles an attacker's. I evaluated each detection on process lineage and behaviour, separated legitimate developer activity from genuinely suspicious patterns, and scoped exclusions narrowly rather than switching protection off.

Takeaway Modern tooling needs detections judged on evidence, not silenced to stop the noise.

OSINT & attribution Impersonation fraud: from bait to attribution An attacker impersonating a legitimate entity was traced and reported to law enforcement.
  1. Engaged the attacker through a controlled persona of the type they were targeting.
  2. Sustained the engagement long enough to collect attribution evidence.
  3. Used open-source intelligence to build an identity and infrastructure profile.
  4. Compiled the evidence into a package for law enforcement.

Outcome Attribution evidence submitted to law enforcement agencies.

Threat intelligence Phone-scam network intelligence Callers impersonating legitimate organisations, mapped from scattered clues.
  1. Collected the details the callers left behind across each interaction.
  2. Correlated them with open-source data to identify the operators and linked accounts.
  3. Built a full picture of the group, including locations.
  4. Submitted the findings to law enforcement with the case.

Outcome Intelligence handed to law enforcement for action.

Work with me

For companies, startups, institutes and teams that need hands-on security help. Available for freelance projects, training engagements and full-time roles.

  • Penetration testing & VAPT

    Web applications, infrastructure and external attack surface, with a clear report and a retest.

  • Detection & response setup

    SIEM, EDR, XDR and SOAR deployment, use cases and tuning that cut the noise.

  • Incident response support

    Triage, containment, investigation and recovery guidance when something goes wrong.

  • Hardening reviews

    Endpoints, servers, email and Microsoft 365 configured to resist real attacks.

  • Training & awareness talks

    Sessions for schools, colleges, institutions and teams on today's threats.

  • Security tool POCs

    Independent hands-on evaluation before you commit to a security product.

Speaker & mentor

I run cyber crime awareness sessions for schools, colleges and institutions: how today's scams and attacks actually work, and the habits that stop them. Tap a topic to see what audiences take away.

  • Schools
  • Colleges
  • Institutions

Been targeted? In India, report cyber fraud straight away on helpline 1930 or at cybercrime.gov.in. The faster it's reported, the better the chance of stopping the money.

Invite me to speak

Technology stack

Grouped by capability. Platforms I have implemented, operated or tested with.

Endpoint, EDR, XDR & MDR

  • SentinelOne
  • Field Effect
  • Huntress
  • Trend Micro Worry-Free
  • ScreenConnect

SIEM, SOAR & analytics

  • Splunk Enterprise
  • Splunk ES
  • Splunk SOAR
  • Splunk ITSI
  • Perch SIEM
  • SPL

Email, identity & cloud

  • Microsoft 365
  • Exchange Online
  • Entra ID
  • Trend Micro Email Security
  • Proofpoint
  • Hornetsecurity
  • Google Workspace
  • Okta
  • Active Directory

Offensive security

  • Kali Linux
  • Nuclei
  • Nikto
  • WPScan
  • Horizon3.ai NodeZero
  • Vonahi

Vulnerability & exposure

  • Qualys VMDR
  • Dark Web ID
  • Dehashed

Network & secure access

  • Zscaler ZIA
  • Zscaler ZPA
  • Client Connector
  • NSS
  • Firewall telemetry

Threat intel & OSINT

  • VirusTotal
  • AbuseIPDB
  • SpiderFoot
  • Amass
  • Recon-ng
  • theHarvester
  • Sherlock

Awareness

  • KnowBe4
  • BullPhish ID

Platforms

  • Linux
  • Windows
  • macOS
  • VPS & cloud labs

Professional journey

From security operations to security engineering and offensive security.

  1. Senior Implementation Specialist (Security SME)

    Promoted from Cybersecurity Engineer

    Threat detection and incident response across multiple EDR, XDR and MDR platforms: alert triage, investigation, containment and mitigation. Endpoint hardening, email and identity security, vulnerability management, penetration testing, phishing awareness and dark web monitoring.

  2. Associate Consultant

    SIEM and SOAR engineering with 100+ use cases, log onboarding, dashboards, Zscaler implementation and autonomous penetration testing.

  3. SOC Analyst

    Security monitoring, alert triage, investigation, escalation and reporting.

  4. Internships & bug bounty

    Cybercrime investigation and security research internships, and bug bounty hunting.

  5. B.Tech, Electronics & Telecommunication Engineering

    Followed by a Master's program in cybersecurity.

Labs & research

What I keep practising and building outside client work.

  • Red team simulations and attack labs
  • Malware and behavioural analysis
  • EDR behaviour and detection testing
  • SIEM detection engineering and SOAR automation
  • Web application and WordPress security
  • Linux and Windows hardening
  • OSINT tooling and investigations

Certifications

EC-Council Certified Ethical Hacker (CEH)

Also certified

  • Certified Cyber Criminologist
  • Splunk Enterprise Certified Admin
  • Splunk Core Certified Power User
  • Zscaler ZIA
  • Qualys VMDR

Next up

  • CPENT
  • OSCP

Let's talk security

Freelance projects, training sessions, speaking or full-time roles: tell me what you need.

Esc