Application Security · SOC · Linux Systems

Mohammad
Favas S

AppSec · VAPT · SOC Analyst · Linux Systems Engineer

Information Security researcher specializing in web application security, source-code analysis, and custom defensive tooling. Verified record of code-level remediation in the open-source ecosystem - including an upstream patch for a structural improper access control flaw in the NLTK Python framework (CVE-2026-12261). Experienced in automated threat intelligence pipelines, CIS-benchmarked Linux hardening, API security assessment, and building zero-dependency security tooling.

Kollam, Kerala, India 3 published writeups Open to security roles
About

I find the flaw.
Then I fix it.

"Anyone can report a vulnerability. I wanted to know if I could fix one."

That question changed the way I approached cybersecurity.

When I first started learning security, I thought the goal was to find bugs. The more time I spent reading source code, reversing applications, and understanding how systems were built, the more I realized that discovering a vulnerability is only half the story. The real challenge is understanding why it exists - and how to eliminate it without breaking everything around it.

That mindset led me down a path I didn't expect. I spent countless hours exploring web applications, APIs, Linux systems, and open-source projects. Sometimes that meant reproducing exploit chains. Other times it meant writing small tools in Python or Go to automate repetitive work. Every project taught me something different, but they all had one thing in common: I wanted to understand systems, not just attack them.

Eventually, that curiosity led me to discover an improper access control flaw in the NLTK framework. Instead of stopping after proving the issue, I traced the root cause, built a proof of concept, developed a patch, and worked through the upstream review process until the fix was merged. Seeing code I wrote become part of a project used by developers around the world was one of the most rewarding moments of my journey.

Since then, I've worked across application security, Web Application VAPT, API security, Linux hardening, and detection engineering. I've reproduced vulnerabilities in production-like environments, built threat intelligence pipelines processing over 55,000 indicators, developed lightweight security tooling, and automated workflows that make security analysis faster and more reliable.

What excites me most is working where software engineering and cybersecurity meet - reading code, understanding architecture, collaborating with developers, and helping build secure software from the inside out.

I'm still learning every day. Cybersecurity has a way of reminding you that there's always another system to understand and another problem worth solving.

Don't just find vulnerabilities. Understand them. Fix them. Learn from them.

Current focus
  • Web application & API penetration testing (VAPT)
  • Detection engineering & SIEM orchestration (Wazuh)
  • Linux system hardening & CIS compliance
  • Open-source vulnerability research & responsible disclosure
  • CTI enrichment pipeline & custom security tooling
Certifications
Apr 2026
Certified SOC Analyst (CSA)
EC-Council • Cert No. ECC3194250687
May 2026
Docker: Foundations Professional Certificate
Docker • Official Foundations Certification
2026
Certified in Cybersecurity (CC)
ISC2 • Final Assessment Completed
Active
TryHackMe Security Rankings
TryHackMe • Top 1% Global | 21 Badges
Education
2025 - 2026
Certified IT Infrastructure & Cyber SOC Analyst
RedTeam Hacker Academy • Cyber Security & SOC Operations
2021 - 2025
B.Tech, Computer Science & Engineering
Vidya Academy of Science & Tech Technical Campus • CGPA: 7.56/10
Projects

Selected work.

GitHub
Threat Intelligence Pipeline & Wazuh Detection Engineering
Blue Team CTI Automation

Threat Intelligence Pipeline & Wazuh Detection Engineering

Architected a Python CTI pipeline ingesting 55,000+ IOCs per run from URLhaus, Feodo Tracker, and AlienVault OTX. Built a weighted confidence-scoring engine ranking 45,000+ indicators by recency, source trust, and corroboration - exporting 1,800+ IPs and 1,600+ domains into Wazuh CDB lists with automatic SIEM hot-reload. Enriched high-confidence IOCs via AbuseIPDB and VirusTotal; authored custom Wazuh rules mapped to MITRE ATT&CK T1071. Automated on a 6-hour systemd timer cycle.

Linux Infrastructure Hardening & SIEM Orchestration
CIS Compliance & Detection Stack

Linux Infrastructure Hardening & SIEM Orchestration

Audited Arch Linux against CIS Benchmark v3.0, remediating 100+ misconfigurations to lift SCA compliance from 26% to 83%. Deployed 22,000+ auditd rules (Neo23x0 baseline) for kernel-level telemetry and MITRE ATT&CK-mapped detection. Hardened via kernel module blacklisting, noexec/nosuid/nodev mounts, and sysctl protections. Containerized Wazuh for real-time FIM, SCA scoring, and SOC-style triage.

Peelr
Lightweight JavaScript Security Scanner

Peelr

Engineered a lightweight, concurrent CLI security utility in Go (stdlib-only) for automated client-side reconnaissance. Implements high-performance regex pattern matching to extract API keys, hardcoded secrets, hidden endpoints, and sensitive exposure strings from local and remote JavaScript source files. Surfaces risk scores via CLI and local web UI with scan history and diff support.

NetPulse
Real-Time Network Telemetry HUD

NetPulse

Developed a lightweight, real-time network diagnostic tool for Linux in Go using goroutines for zero-dependency terminal-based telemetry. Concurrently monitors gateway latency, interface throughput (RX/TX speeds), and backbone packet loss metrics. Engineered raw ICMP socket capabilities with unprivileged fallback and a circular buffer interface for real-time network alerts and background daemon mode.

Skills

Tools & platforms.

Application Security & VAPT
Web Application VAPT OWASP Top 10 API Penetration Testing Secure Code Review Burp Suite Postman Metasploit Exploit Replication
Detection Engineering (SOC & SIEM)
Wazuh Alert Triage Log Correlation MITRE ATT&CK auditd FIM SCA SIEM Tuning IOC Analysis
Linux & Infrastructure
Arch Linux Debian Ubuntu Kernel Hardening systemd PAM CIS Benchmarks SSH Hardening UFW Apache Nginx
Threat Intelligence & CTI
IOC Enrichment Wazuh CDB Lists AbuseIPDB VirusTotal MITRE ATT&CK Mapping Threat Correlation
Network & Traffic Analysis
Wireshark Nmap Packet Analysis TCP/IP DNS HTTP/S Firewall Config
Scripting & Automation
Go (Golang) Python Bash SQLite Docker Git Regex Concurrent Automation
Experience

Work history.

Apr 2024 - Sep 2025
Freelance Software Developer
Developed and deployed applications with secure coding, input validation, authentication controls, API handling, and basic security monitoring in mind. Performed manual review, testing, and remediation during delivery to reduce attack surface while keeping applications reliable, performant, and easier to troubleshoot.
Writeups

Research & notes.

All writeups

🛰️ Threat Intel Aggregation & IOC Enrichment Pipeline

Technical writeup for a Blue Team CTI pipeline that ingests open-source IOCs, deduplicates and scores them, enriches high-confidence indicators, and exports live Wazuh CDB detection lists.

Read writeup

🐧 Linux Infrastructure Hardening & SIEM Orchestration

Technical walkthrough covering the remediation of 100+ misconfigurations on a minimalist Arch Linux endpoint to achieve an 83% CIS Benchmark score. Demonstrates a defense-in-depth methodology, shifting from a vulnerable baseline to a production-hardened posture via layered kernel, filesystem, and identity-level controls.

Read writeup

🧅 Peelr: JavaScript Recon And Triage

Peelr is a stdlib-only Go tool for JavaScript recon and triage. It analyzes remote or local .js files, highlights secrets, endpoints, risky sinks, and paths, then presents results through a CLI, web UI, and scan history.

Read writeup
Contact

Get in touch.

Open to cybersecurity roles, freelance work, security research conversations, and tool collaborations.

Send email