Shreenkhala Bhattarai

Shreenkhala Bhattarai

Head of Security Operations

Cybersecurity Practitioner • Security Researcher

Building stronger security operations, detection capabilities, and practical cybersecurity knowledge.

SIEM · SOC · Incident Response · Threat Hunting
DFIR · Threat Intelligence · Security Automation

Introduction

Security operations, done deliberately.

  • SOC & Security Operations
  • SIEM & Detection Engineering
  • Incident Response
  • Threat Hunting
  • DFIR
  • Threat Intelligence
  • Security Automation
  • Security Monitoring

I'm Shreenkhala Bhattarai, Head of Security Operations at CryptoGen Nepal. I've spent the last several years inside a 24/7 SOC: first as an analyst on shift, then leading the team, and now running the operation. I work across SIEM, incident response and threat hunting, with a particular interest in turning security data into useful detections.

Alongside operations I research things like detection bypass, logging strategy and SOC effectiveness, and publish InfoSec Stories. I also teach cybersecurity and mentor incident response practitioners.

Tools I work withLogRhythm · Logpoint · FortiSIEM · Splunk · Wazuh · Fortinet · TheHive · Cortex · Zeek · Suricata

Kathmandu, Nepal · More about me → ·Experience →

Projects & Research

Selected work

All projects & research →

Initiative2024 - PresentActive

InfoSec Stories

A long-term body of practical cybersecurity knowledge, research, analysis, projects and lessons drawn from real security operations work.

Writing & research · SIEM · Windows internals · Linux

Research2023 - PresentOngoing

Threat Hunting Research

Hypothesis-driven hunts across client environments, including research into detection bypass techniques in Active Directory and how to close those gaps.

MITRE ATT&CK · Windows Event Logs · Sysmon · Zeek · Suricata

Project2022 - PresentOngoing

Detection Engineering Use Cases

A structured lifecycle for SIEM detection content, from threat research and use case design through testing, tuning and measurable ATT&CK coverage.

SIEM correlation rules · MITRE ATT&CK · Sigma-style logic · AttackIQ

Initiative

InfoSec Stories

Research, detection guidance, project write-ups and lessons learned from years inside security operations.

Explore InfoSec Stories

Field Notes

From the InfoSec Professional Desk

All articles →