Skip to content
View Kalla-Bhanu's full-sized avatar

Block or report Kalla-Bhanu

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Kalla-Bhanu/README.md

Animated security engineering dashboard for Bhanu Kalla

Animated security engineering typing line

LinkedIn profile GitHub repositories Detection engineering AWS security

Mission Control | Start Here | Defense Labs | How I Defend | Security Arsenal | Professional Signal


Mission Control

Mission control dashboard with security engineering metrics

I build blue-team systems that turn security telemetry into clean detections, enriched evidence, and repeatable response paths. My strongest lane is detection engineering across cloud, identity, endpoint, email, DLP, SIEM, and automation workflows.

Primary lane     Detection engineering, SIEM tuning, cloud defense, alert validation
Operating style  Risk story -> telemetry check -> detection logic -> enrichment -> runbook
Core tooling     Splunk SPL, Datadog monitor-as-code, AWS, Python, CrowdStrike, Defender, Prisma/Cortex
Outcome          Faster analyst decisions backed by clean evidence

Start Here

Defense labs dashboard showing prioritized portfolio projects

Best first click Why it matters
Cloud Detection Engineering Platform Capstone cloud detection lab connecting synthetic AWS events, detections-as-code, expected alerts, validation, runbooks, dashboard artifacts, and public-safe evidence.
Datadog Detection Engineering Lab Detection-as-code discipline: monitor logic, validation harnesses, negative controls, CI checks, ATT&CK mapping, and runbooks.
CloudSec Detection Lab AWS-first cloud defense with CloudTrail, IAM, STS, S3, EKS, KMS, Lambda replay, and evidence templates.

Defense Labs

Lab What it proves
Cloud Detection Engineering Platform Public-safe cloud detection engineering with synthetic AWS events, detections-as-code, expected alerts, validation, runbooks, dashboard artifacts, and CI checks.
Datadog Detection Engineering Lab Monitor-as-code, validation, tuning, CI verification, ATT&CK mapping, and triage runbooks.
CloudSec Detection Lab Cloud detection engineering with AWS telemetry replay, identity/cloud context, and analyst-ready evidence.
SaaS Attack Chain Detection Lab SaaS threat modeling with Okta, Google Workspace, Atlas activity, Sigma-style rules, and public-safe artifacts.
security-ml-threat-detection Security analytics, anomaly detection, feature engineering, and high-risk behavior modeling.
soc-monitoring-credit-approval Incident workflow monitoring for sensitive financial and PII processes.
SMART-ATS Product engineering with document parsing, workflow automation, and practical AI-assisted UX.

How I Defend

Security engineering workflow dashboard from risk story to evidence

Phase What I care about
Model the risk What behavior matters, which asset is exposed, and what outcome would hurt.
Validate telemetry Source freshness, schema quality, identity joins, missing context, and false-positive pressure.
Build the detection Explainable logic mapped to behavior and tested with positive and negative cases.
Package response Evidence path, triage questions, escalation notes, and tuning history.

Security Arsenal

Security engineering tools

Detection & SIEM Cloud & CNAPP Identity, Endpoint & Email Automation & Response
Splunk SPL AWS CloudTrail Entra ID / Azure AD Python
Datadog monitor-as-code GuardDuty / Security Hub Duo / Okta concepts Bash / PowerShell
Sigma-style rules IAM / STS / KMS / S3 CrowdStrike Falcon ServiceNow / Jira
ATT&CK mapping Prisma / Cortex Cloud Microsoft Defender / O365 Runbooks / RCA
False-positive tuning Vulnerability context Proofpoint concepts GitHub Actions

Professional Signal

Experience and education dashboard

Role Signal
Security Engineer, American Express Detection lifecycle work across identity, email, endpoint, cloud, DLP, and vulnerability-risk domains.
Security Analyst, Northeastern University Endpoint, identity, phishing, access review, firewall, SIEM, and ServiceNow investigation workflows.
Security Analyst Intern, FILESIE SIEM alert analysis, ATT&CK/OWASP-aligned tuning, attack-path modeling, control validation, and Python dashboards.
Education Timeline
Northeastern University, Master of Professional Studies in Information Security Management 2023 - 2025
GITAM University, Visakhapatnam, B.Tech in Computer Science and Engineering 2019 - 2023

Building Next

roadmap.status = "active"
current.signal = "Cloud Detection Engineering Platform"
next.quality   = "richer synthetic telemetry, validation harnesses, negative controls, and tuning history"
next.story     = "cleaner incident narratives that connect alerts to analyst decisions"

Dark security footer wave

Pinned Loading

  1. Cloud-Detection-Engineering-Platform Cloud-Detection-Engineering-Platform Public

    Public-safe cloud detection engineering lab with synthetic AWS events, detections-as-code, expected alerts, runbooks, validation, and dashboard.

    JavaScript

  2. Datadog-Detection-Engineering-Lab Datadog-Detection-Engineering-Lab Public

    Detection engineering lab with Datadog monitor-as-code, validation harnesses, negative controls, CI checks, ATT&CK mapping, tuning history, and triage runbooks.

    JavaScript

  3. CloudSec-SOC-Detection-Lab CloudSec-SOC-Detection-Lab Public

    AWS-first SOC detection engineering lab with CloudTrail/IAM/STS/S3/EKS/KMS telemetry, Lambda replay, dashboards, evidence templates, and analyst runbooks.

    HTML

  4. SaaS-Attack-Chain-Detection-Lab SaaS-Attack-Chain-Detection-Lab Public

    SaaS attack-chain detection lab across Okta, Google Workspace, and MongoDB Atlas with Sigma-style rules, validation bundles, and public-safe evidence.

    HTML

  5. security-ml-threat-detection security-ml-threat-detection Public

    ML security analytics lab for anomaly detection, feature engineering, and high-risk user/entity behavior investigation.

    Python

  6. soc-monitoring-credit-approval soc-monitoring-credit-approval Public

    SOC monitoring and incident investigation lab for financial/PII workflows with alerts, dashboards, evidence, and response notes.

    Python