Skip to content
View 4nshumaan's full-sized avatar

Highlights

  • Pro

Block or report 4nshumaan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
4nshumaan/README.md

Hi there, I'm Anshumaan Mishra! πŸ‘‹

πŸ” Cyber Automation Engineer | Security Researcher | SOC Analyst

LinkedIn Email Phone


πŸš€ About Me

Cyber Automation Engineer at North Dakota IT specializing in SOAR, incident response, and threat detection. I build automated security solutions that reduce alert fatigue and improve response times.

Current Focus: Building agentic SOC assistants with LLMs, container security tools, and SOAR playbook automation.


πŸ’Ό Experience

πŸ”Ή North Dakota IT - Cyber Automation Engineer (Dec 2024 - Present)

  • Developed Python scripts to automate security tasks, reducing MTTR by 30%
  • Monitored 10+ EDR alerts weekly, lowering false positives by 20%
  • Built SOAR playbooks that reduced alert fatigue by 45%
  • Used SPL/XQL queries on Splunk/Cortex XSIAM, improving threat detection by 20%

πŸ”Ή Changing the Present - Cybersecurity Intern (Aug 2024 - Dec 2024)

  • Performed security design reviews on SaaS infrastructure to validate security measures put in place
  • Translated security vulnerabilities into business impact through presentations for non-technical stakeholders
  • Tuned detection rules in cloud SIEMs to increase visibility across cloud assets and built playbooks for faster alert triage

πŸ”Ή Westfield Insurance - Information Security Intern (May 2024 - July 2024)

  • Built APIs for security telemetry across 5,000+ assets
  • Created CI/CD pipeline, reducing deployment time from 10 to 4 hours
  • Led vulnerability remediation, utlizing the asset inventory tool to reduce vulnerability backlog

πŸ”Ή Zummit Infolabs - Python/Django Intern (Aug 2021 - Oct 2021)

  • Built Django backend integrations with MySQL databases
  • Automated deployments using Fabric and Ansible

πŸš€ Featured Projects

πŸ€– Agentic SOC Assistant

Ollama, LangChain, Tines, Splunk, FastAPI

  • AI-powered SOC assistant that automates alert triage using 20B-parameter LLM
  • Reduces MTTR by 40% through automated SOAR playbook mapping
  • Maps Splunk alerts to appropriate incident response workflows

🐳 Container Security Scanner

Golang, Docker, Linux

  • Automated vulnerability detection for Docker containers
  • Real-time dashboard with security insights and remediation guidance
  • Covers 5,000+ containers with 99.8% visibility

πŸ“§ Email Automation Extension

JavaScript, Gmail.js, Chrome Extensions

  • Chrome extension for automated follow-up emails based on labels
  • Smart scheduling with customizable intervals
  • Improves response rates from 35% to 67%

πŸ› οΈ Technical Skills

Security Tools: CrowdStrike Falcon, Splunk ES, Cortex XSIAM, Wazuh, Wireshark, Tenable, Volatility, TheHive

Programming: Python, Golang, Bash, SQL

Cloud: AWS (EC2, EBS, CloudTrail, GuardDuty), Azure (AD, Defender for Cloud)

AI/ML: Ollama, LangChain, FastAPI

Other: Docker, VS Code, Jupyter, ServiceNow, Linux, Windows


πŸ† Certifications

πŸ” CompTIA Security+
🐍 GIAC Python Coder (GPYC)
☁️ Microsoft Azure Security Engineer (AZ-500)


πŸŽ“ Education

Master of Engineering in Cybersecurity - University of Maryland, College Park (2022-2024)

Bachelor of Technology in Computer Science - SRM University, India (2018-2022)


πŸ“Š GitHub Stats

GitHub Stats

Top Languages


οΏ½ Let's Connect!

I'm interested in discussing cybersecurity automation, threat detection, and security tooling. Open to collaboration opportunities and industry discussions.

LinkedIn Email


"Automating cybersecurity to make the digital world safer, one script at a time."

Profile Views

Pinned Loading

  1. Network-Log-Analyzer- Network-Log-Analyzer- Public

    Python

  2. API-Hunter API-Hunter Public

    Scripts for API security

    Go

  3. DevSecOps-pipeline DevSecOps-pipeline Public

    Engineered a pipeline using AWS EC2, Jenkins, SonarQube, Prometheus, Grafana, ArgoCD

    HCL

  4. Django-Security Django-Security Public

    Learning to secure aan application written using Django framework

  5. password-strength-meter password-strength-meter Public

    Python

  6. nestjs-task-management nestjs-task-management Public

    TypeScript