Cybersecurity / Blue Team

Bhanu Bastola

Aspiring SOC Analyst · BCA Student · Cybersecurity Enthusiast

STATUS: OPEN TO SOC ANALYST INTERNSHIPS
Focus Blue Team & SOC
Training Cybersecurity Apprenticeship · TryHackMe SOC L1
Education BCA
Based in Nepal

01 / Profile

Summary

BCA student with hands-on SOC training via a 3-month cybersecurity apprenticeship and TryHackMe's SOC Level 1 path. Experienced in alert triage, SIEM platforms (Splunk, Elastic Stack), DFIR fundamentals, and threat detection workflows. Seeking a SOC Analyst internship to contribute to Nepal's growing cybersecurity operations.

02 / Case Studies

How I've approached real triage scenarios

Practiced in simulated SOC environments (TryHackMe labs). Each write-up below is my own reasoning and sanitized evidence, not a course completion badge.

#CASE-001 · Double-Extension File Creation Alert Triage Simulated SOC Env.
Scenario

A SIEM alert fired for a file created with a double extension (e.g., disguising an executable as a document), flagged High severity on the SOC dashboard.

Process

Reviewed the alert details and description, extracted the file's MD5 hash, and cross-referenced it against VirusTotal to check for known-malicious detections.

Evidence Screenshot of VirusTotal results showing the file hash and detection status
Decision

Classified as a true positive: the hash returned multiple malicious detections on VirusTotal, confirming the file was not a legitimate document and matched a phishing-delivered payload pattern rather than benign user activity.

Outcome

Recommended isolating the affected host, blocking the file hash at the endpoint/network level, and flagging the delivery vector (likely email) for user-awareness follow-up.

#CASE-002 · Endpoint Artifact Review (DFIR Intro) Simulated SOC Env.
Scenario

An endpoint showed an unexpected process spawning from a user-facing application, prompting a closer look at what ran on the host around that time.

Process

Reviewed process lineage and file system artifacts to establish a timeline, identified the parent-child process relationship, and checked the spawned process against expected application behavior.

Evidence Screenshot of process tree and file artifacts showing the unexpected process relationship
Decision

Flagged as suspicious pending further review: the process relationship didn't match normal application behavior, warranting escalation rather than a same-session closure.

Outcome

Documented the timeline and indicators for handoff, and noted what additional log sources would confirm root cause.

03 / Technical Skills

What I work with

SOC & Blue Team

SIEM — Splunk, Elastic Stack (ELK) Developing
Alert Triage & Incident Reporting Developing
SOAR & EDR Concepts Learning
Digital Forensics & Incident Response Learning
Threat Detection & Log Analysis Developing

Networking & OS

Network Security & Vulnerability Analysis Developing
Linux Administration & Bash Scripting Developing
DNS, HTTP/S, TCP/IP Protocols Developing

Programming & Tools

Python (scripting & automation) Developing
HTML, CSS, JS Developing
SQL & Database Management Developing
Git / GitHub Developing
Developing — applied hands-on, still building depth Learning — studying the fundamentals

04 / Certifications & Training

Credentials in progress

In Progress

TryHackMe SOC Level 1

Alert Triage, SIEM, DFIR, EDR, SOAR

Completed 2022–23

Bikalpa Fellowship

Certificate of Achievement — Bikalpa - An Alternative

Participation

Koshi Mini Yantra 02

Participation Certificate — Technical Competition

05 / Experience

Where I've trained

Cybersecurity Apprenticeship

Skill Shikshya
2026 – Present
  • Hands-on cybersecurity training covering network security and threat analysis
  • Studied penetration testing concepts, network vulnerabilities, and digital forensics
  • Applying SOC workflows and defensive security skills in a real-world context

Bikalpa Fellow

Bikalpa – An Alternative
2022 – 2023
  • Year-long fellowship on leadership, capacity building, and networking
  • Organised and facilitated a student outreach programme on entrepreneurship

06 / TryHackMe

temporaryus3r · Lv. 0x6 [VOYAGER]

First Step into SOC SOC Apprentice First Alert Closed First Scenario Completed 100% True Positive Rate Defensive Toolsmith cat linux.txt

07 / Education

Academic background

Bachelor in Computer Application (BCA)

Nihareeka College, TU
2021 – Present (7th Sem)

+2 Management

Merryland College, NEB
2020

S.E.E.

Pokhariya Secondary School, NEB
2018

08 / Soft Skills

How I work

Leadership Critical Thinking Team Collaboration Time Management Public Communication