NEW SOC ALERTProfile activity detected.
SOC CONSOLE // NEW PROFILE ALERT

Subject activity requires review.

Source: Forensic Science → Cybersecurity. Select the analyst action that makes the most sense.

STATUS // awaiting analyst action
LEVEL 01 // SOC L1
Subject identification & triageUnlock About + Analyst Toolkit
ABOUT

How I ended up here

Forensic science came first. Cybersecurity grew out of the same habit: I like understanding what actually happened.

“Finding an answer is useful. Understanding how you got there is the part I enjoy.”

I started with Forensic Science, and it shaped the way I look at problems. If something happened, I wanted to know how. If two pieces of evidence did not seem to match, I wanted to understand why. And if I reached a conclusion, I wanted to know what actually supported it.

That habit followed me into digital investigations. During my forensic work, I handled different kinds of evidence and worked across fraud and cybercrime cases — from emails, metadata and digital artifacts to questioned documents, fingerprints and audio/video evidence.

Cybersecurity became the part I wanted to understand more deeply. What interested me was not only learning the names of tools or attacks, but what happens after something suspicious appears: how an analyst decides whether it matters, what happened before it, what evidence supports the conclusion, and what should be checked next.

That is what pulled me toward SOC operations, incident response, threat investigation, phishing analysis, Windows endpoint investigation and digital forensics.

I am still learning, and I want this portfolio to show that journey rather than pretend I already know everything.

I like investigating things until I understand the story behind them.
L1 // ANALYST TOOLKIT

Skills as a SOC knowledge graph

The tools are connected because the work is connected: signals become context, context becomes investigation, and investigation becomes a response decision.
HOVER NODES // RELATIONSHIPS ARE VISUAL, NOT PROFICIENCY SCORES
LEVEL 02 // SOC L2
Correlation & professional contextUnlock Experience
EXPERIENCE

Work that shaped how I operate

Investigation, evidence, people, targets and accountability — different environments, useful lessons from both.

Forensic Expert

Spylens Forensic Investigation · Vashi, India · 2024–2025
INVESTIGATION · EXAMINATION · ANALYSIS

Worked across 10+ fraud and cybercrime investigations, examining and analysing evidence to understand what happened and document findings. Digital evidence was an important part of the role, but the work also included questioned documents, fingerprints and audio/video-related evidence.

INVESTIGATION FOCUS
Case InvestigationDigital ForensicsEmail & Cybercrime InvestigationEvidence ExaminationEvidence PreservationForensic Reporting
  • Investigated fraud, cybercrime and forensic matters by examining available evidence, identifying relevant findings and contributing to case conclusions.
  • Worked with digital evidence including emails, files, metadata, timestamps and other electronic artifacts.
  • Examined email-related evidence including headers, sender information, routing, timestamps, metadata and associated files.
  • Performed disk imaging and forensic acquisition while preserving original evidence.
  • Used MD5/SHA-based hash verification to support evidence integrity.
  • Maintained chain-of-custody and evidence-handling documentation.
  • Examined metadata, timestamps, file properties and digital artifacts to reconstruct activity.
  • Performed steganography-related examination where relevant.
  • Worked with questioned documents and fingerprint-related forensic examination.
  • Worked with voice/video evidence and related examination processes.
  • Documented procedures, observations, evidence handling and findings in forensic reports and case records.
  • Approached conclusions through evidence correlation rather than relying only on the initial allegation or assumption.

Business Associate

Stellar Organisation · Andheri, India · 2025–2026
B2B · B2C · LEADERSHIP

Worked in a target-driven sales environment across B2B and B2C sales, client acquisition, customer relationships, CRM, team coordination, recruitment, training and documentation. The role taught me how to communicate clearly, work with people, own a target and stay accountable for the result.

🏆 Top Revenue PerformerGenerated the highest revenue during an internal sales competition and finished as the top-performing participant for that period.
CORE RESPONSIBILITIES
B2B SalesB2C SalesClient AcquisitionRelationship ManagementCRMTeam LeadershipRecruitmentTraining
  • Worked across B2B and B2C sales and direct customer/client interaction.
  • Handled client acquisition, ongoing relationships and account retention.
  • Managed a team of four and supported day-to-day coordination and performance.
  • Participated in hiring, candidate screening and recruitment activities.
  • Supported onboarding and training of new team members.
  • Handled customer/account documentation and verification.
LEVEL 03 // SOC L3
Investigation, evidence & archived researchUnlock Investigations, Learning, Research & Contact
INVESTIGATIONS

Not just what I found — how I got there

These are text-led case studies. Each one walks through where I started, what I checked, what changed my thinking, what I could confirm and what I learned.
CASE 01 · FORENSIC CASEWORK

Email Phishing & Digital Forensic Investigation

A forensic email investigation involving evidence preservation, header and metadata analysis, attachment hashing, VirusTotal, sandbox review and steganographic examination — with the findings considered together rather than trusting a single tool.

Email & headersMetadataHashesThreat intelligenceSandboxSteganography
READ THE INVESTIGATION →
CASE 02 · INDEPENDENT INVESTIGATION

Windows Endpoint Persistence Investigation

A recurring black console window kept returning after the visible process was stopped. The investigation moved from identifying the process to tracing what kept launching it — eventually leading to scheduled-task persistence.

Process ExplorerProcess MonitorTask SchedulerPersistenceContainmentValidation
READ THE INVESTIGATION →
CASE 03 · SOC LAB

SOC Incident Response Lab — Hack The Box Academy

A structured SOC learning case focused on what happens after an alert appears: triage, context, investigation, MITRE ATT&CK mapping, incident creation, response, documentation and handoff.

EventAlertTriageInvestigateIncidentDocument / Handoff
READ THE INVESTIGATION →
CERTIFICATIONS

What I’ve learned along the way

Courses, credentials, and learning milestones that added something useful to the way I work.
Incident Handling ProcessHack The Box Academy
SOC AnalystCybrary
Fortinet Certified FundamentalsFortinet Training Institute
Fraud and Forensic AuditRiskpro India
Foundations of CybersecurityGoogle
Advanced CybersecurityGreat Learning
RESEARCH & ACADEMIC WORK

Different subjects. Same instinct to investigate.

The subjects are very different from cybersecurity. The part I carried forward is the process: start with a question, work through the available information, compare evidence and be careful about what the material actually supports.
01 · PUBLISHED RESEARCH · SPRINGER

Conducting a Diatom Study in Various Regions of Maharashtra (Nagpur, Amravati, Wardha) with the Aim of Identifying Potentially Undiscover Species by Compound Microscope

Author: Kamdi Tanvi · Book: The Green Revolution: Building Sustainable Solutions

Microscopy-based research across Nagpur, Amravati and Wardha involving observation, sample/data comparison, documentation and analytical reporting. It gave me early experience turning a research question into a structured investigation and a defensible written conclusion.

READ PUBLICATION ↗
02 · UNDERGRADUATE ACADEMIC REVIEW · FORENSIC SCIENCE

The Study of Cannibalism

This was a mandatory undergraduate review paper completed as part of my Forensic Science degree. Rather than conducting experimental work, we studied the subject through existing literature and documented cases — beginning with definitions and historical context, then reviewing reported cases, patterns described in the literature and health consequences discussed in scientific sources.

The review included Kuru, a rare fatal prion disease historically associated with specific practices of mortuary cannibalism. We also organised information from the literature and case material into a structured academic analysis.

Looking back, the subject is obviously far removed from cybersecurity. What feels familiar is the method: take a difficult question, compare multiple sources, look for patterns, and separate what the evidence supports from what it does not.

University submission · Not a published paper · No verified digital copy currently available
FINAL VERDICT // CONTACT

Every analyst starts somewhere. The right opportunity is what turns potential into experience.

If what you have seen here looks worth a conversation, make the final call.
CASE STATUS // AWAITING YOUR VERDICT

I have shown you how I think, what I have investigated, what I have built, and what I am still learning. If you think I am worth the opportunity, mark this profile as a True Positive and let’s connect.

VERDICT CONFIRMED // CONNECTION CHANNELS OPEN
CALL // +91 93075 95845 EMAIL // tanvikamdi38@gmail.com