Yamini Savalia

Yamini Savalia

Mentor
Rising Codementor
US$8.00
For every 15 mins
ABOUT ME
IT Security Analyst with over 5 years of experience
IT Security Analyst with over 5 years of experience

As a certified cybersecurity professional, I have had the privilege of mentoring and training individuals globally—ranging from students to working professionals—through hands-on workshops and structured courses. My teaching experience includes Networking fundamentals, Secure Software Development, Cybersecurity awareness and career guidance, Android VAPT, malware analysis, and digital forensics.

What drives me to pursue a role as a tutor is the genuine passion I have for sharing knowledge and empowering others to enter and grow in the cybersecurity field. I believe that mentorship is a powerful way to make a lasting impact—not only by strengthening someone’s technical foundation but also by guiding them through real-world scenarios and career transitions.

Pacific Time (US & Canada) (-07:00)
Joined May 2025
EXPERTISE
5 years experience
4 years experience
5 years experience
7 years experience
4 years experience
2 years experience

REVIEWS FROM CLIENTS

Yamini's profile has been carefully vetted and approved as a Codementor. Connect with Yamini now, and leave a review for them once you're done!
SOCIAL PRESENCE
GitHub
Splunk-Security-Monitoring
0
0
threat-hunting-foothold
0
0
EMPLOYMENTS
Engineer - Information Security
FIS SOLUTIONS(INDIA) PRIVATE LIMITED
2023-11-01-2024-11-01
  • Monitored security events in a 24/7 global SOC to detect potential incidents.
  • Identified and escalated threats such as ph...
  • Monitored security events in a 24/7 global SOC to detect potential incidents.
  • Identified and escalated threats such as phishing and ransomware following defined procedures.
  • Tuned security device rules based on incident review findings.
  • Trained analysts on cybersecurity tools and incident handling.
Monitoring
Incident management
Cybersecurity
View more
Monitoring
Incident management
Cybersecurity
Ransomware protection
Phishing analysis
View more
CYBERSECURITY CONSULTANT
FREELANCE
2022-07-01-2023-11-01
  • Delivered online training and workshops to international professionals on Android VAPT, Digital Forensics and Malware Analysis.</...
  • Delivered online training and workshops to international professionals on Android VAPT, Digital Forensics and Malware Analysis.
  • Talked in public forums to raise awareness of cyber crimes.
Malware Analysis
Web Training
Security software
View more
Malware Analysis
Web Training
Security software
Optimal workshop
View more
Security Analyst
HACKIT TECHNOLOGY & ADVISORY SERVICES
2021-03-01-2022-07-01
  • Procured servers, performed hardening, and automated tasks using scripts.
  • Diagnosed and resolved security, network, and s...
  • Procured servers, performed hardening, and automated tasks using scripts.
  • Diagnosed and resolved security, network, and system issues with root cause analysis.
  • Conducted VAPT, source code review, reverse engineering, and malware analysis on Android projects.
  • Conducted phishing attack investigations, sandboxed URLs, APKs, and files; performed on-demand scans and IOC investigations using threat intelligence tools.
Reverse Engineering
Code Review
Scripting language
View more
Reverse Engineering
Code Review
Scripting language
Malware Analysis
Threat intelligence
System security
Procurement
Phishing analysis
Root cause failure analysis
View more
PROJECTS
threat-hunting-footholdView Project
2026
A multi-stage attack simulation across a corporate environment — from initial perimeter breach to active C2 communication — investigated ...
A multi-stage attack simulation across a corporate environment — from initial perimeter breach to active C2 communication — investigated entirely through Elastic SIEM log analysis. The scenario involves no pre-generated alerts or guided triage queues. Detection, correlation, and attribution are driven by raw KQL queries across network, endpoint, and authentication telemetry spanning four compromised hosts. The attack surface covers SSH brute force, web application exploitation, phishing-delivered payloads, process injection, defense evasion, persistence mechanisms, and three simultaneous C2 channels — making this a representative sample of what a real lateral movement investigation looks like in a production SOC environment. The attacker used a layered attack: SSH brute force → web shell → malicious LNK file → process injection → defense evasion → persistence → multi-channel C2 (DNS tunneling + Discord + CDN abuse). Each stage required pivoting between log sources and chaining evidence across hosts.
Linux
Splunk
Elastic Stack
View more
Linux
Splunk
Elastic Stack
KQL
SIEM
View more
Detection Engineering LabView Project
2026
I have spent four years working SOC alerts — triaging EDR hits, investigating phishing, pulling logs during incidents. But at some point ...
I have spent four years working SOC alerts — triaging EDR hits, investigating phishing, pulling logs during incidents. But at some point I started wondering: how do these detections actually get built? Who wrote the original rule that caught the thing I'm investigating? That question is what led to this project. This repo documents my path from learning SPL basics all the way to authoring production-grade detection rules from scratch — picking a real MITRE ATT&CK technique, simulating it in an isolated lab, capturing the actual logs it generates, writing a Sigma rule, converting it to Splunk SPL, and working through every scenario that would cause it to fire incorrectly in production. The detection engineering project (Project 03) took the most time. I ran every technique myself in a lab environment and documented exactly what I observed — including the things that didn't work the way I expected, the detection gaps I found in default Windows configurations, and the places where I had to adapt on the fly.
Splunk
Mitre att&ck
Sigma rules
View more
Splunk
Mitre att&ck
Sigma rules
View more