BLU-BANK
2022 — NOW
Tehran, Iran · Security Engineering
Blue Team Engineer
Designing procedures for Notables and dashboard design
and implementing them.
Designing Asset Management and Patch Management flows.
Developing and tuning Data Models.
Developing Use Cases and Dashboards.
Acting as Security Architect for Kubernetes and implementing
laboratory scenarios for testing, implementation and demos.
Developing a Python-based logging module for Apache Superset
and other tools in different programming languages.
Red / Purple Team Engineer · 2 Years
Adversary Simulation and Emulation.
Developing Red Team tools and malware.
Implementing Red Team scenarios and helping Blue Team
engineers develop detection rules.
Developing a malware analysis platform based on LLM,
MCP and IDA Pro to analyze malware automatically.
EDR bypassing and tuning the rules.
Developing an Access Matrix in Splunk to help Blue Team
engineers implement complex logical Splunk queries.
Hunting unofficial network traffic based on hypothesis hunting.
SOC Analyst · 2 Years
Developing detection rules for different attacks.
Developing a Python module connecting to Splunk using
splunk-sdk and checking queries based on KMeans and
Machine Learning.
Setting up Splunk Data Models for Endpoint, Network
and Authentication.
Developing and tuning Notables based on Data Models.
Investigation using Splunk Investigate and Workbenches.
Developing Auditd rules for Linux.
Basic forensics using FTK, Volatility and related tools.
Detecting DNS tunneling attacks with URL Toolbox.