> booting khan.sec console...
> loading modules [OK]
> verifying auth handlers [OK]
> connecting threat intel feed [OK]
> rendering interface...
KHAN.SEC
Hire me
OPEN TO SOC ANALYST & SECURITY ENGINEERING ROLES
// whoami

Usman Khan

Final-year BCA student who builds defensive security tooling instead of just studying it — SOC dashboards, threat intelligence platforms, and vulnerability scanners, all working Flask applications with real detection logic behind them.

About the analyst

I'm a final-year BCA student focused on the Blue Team side of security — monitoring, detection, and incident response, rather than offense. Most of what I've learned came from building the same kind of tooling a SOC analyst actually uses day to day, not just reading about it.

My projects follow a deliberate progression: a foundational SOC dashboard to nail the fundamentals, then a full analyst-workflow platform (SentinelX) with real threat intel integration, and a network vulnerability scanner built on Nmap. Each one is a complete Flask application — auth, database, detection logic, and reporting — not a UI mockup.

I care as much about how a tool looks and feels to the analyst using it as I do about what it detects — every dashboard here has a distinct, deliberate interface.

roleAspiring SOC Analyst
educationBCA, Final Year
focusBlue Team / Detection
stackPython · Flask · SQL
locationBengaluru, India
status● Open to work

The tooling behind the systems

[ LANG ]

Languages

PythonSQLJavaScriptHTML/CSS
[ BACKEND ]

Backend & Auth

FlaskFlask-LoginSQLAlchemyWerkzeug
[ SEC ]

Security Tooling

NmapAbuseIPDB APIThreat Detection RulesRisk Scoring
[ DATA ]

Data & Reporting

SQLiteChart.jsReportLab (PDF)
[ TOOLS ]

Workflow

GitGitHubVS Code
[ NOW ]

Currently deepening

Threat HuntingIOC CorrelationMITRE ATT&CK

Education & path

2023 — 2026

Bachelor of Computer Applications (BCA)

Final-year student, building a hands-on portfolio of defensive security applications alongside coursework to bridge the gap between theory and real SOC tooling.

In progress

Independent Security Portfolio

Self-directed build of progressively advanced Flask security platforms — SOC Dashboard → SentinelX and beyond — to demonstrate practical blue-team skills for placements.

Deployed systems

01
SentinelX
◆ FLAGSHIP

A complete Security Operations & Threat Intelligence platform simulating real analyst workflows — from raw log ingestion to alert triage, incident investigation, and executive-ready PDF reporting. Built with a navy/indigo glassmorphism interface designed for long monitoring shifts.

SentinelX dashboard
Alert-to-incident promotion with investigation notes
Live AbuseIPDB API + local CSV fallback (graceful degradation)
Animated dashboard counters, circular threat-score gauge
ReportLab PDF reports with KPI cards & bordered incident summaries
PythonFlaskSQLAlchemyChart.jsReportLabAbuseIPDB API
02
SOC Dashboard
◆ FOUNDATIONAL

The foundation of the portfolio — a Security Operations Center dashboard combining a weighted organizational risk-scoring engine with a rule-based threat detection layer that auto-escalates suspicious activity as it happens.

SOC Dashboard
Auto-escalation on brute-force, port-scan & repeat-offender patterns
Weighted 0–100 live organizational risk score
Secure auth — Flask-Login sessions + Werkzeug password hashing
Chart.js analytics + one-click PDF incident reports
PythonFlaskFlask-LoginSQLAlchemyChart.js
03
Vulnerability Scanner
◆ NETWORK RECON

An Nmap-powered scanner that sweeps target IPs for open ports and running services, classifies each finding by risk level against a built-in exposure database, and hands back concrete remediation steps — not just a raw port list.

Nmap-driven port & service discovery (-F -sV)
Risk classification: FTP, SSH, Telnet, HTTP, SMB, RDP & more
Per-finding, actionable remediation recommendations
Downloadable PDF vulnerability assessment report
PythonFlaskpython-nmapReportLab

Certifications

Introduction to Cybersecurity certificate
Click to expand

Introduction to Cybersecurity

Jul 2026
Issued by Cisco Networking Academy
Networking Basics certificate
Click to expand

Networking Basics

Aug 2026
Issued by Cisco Networking Academy
Intro to Splunk certificate
Click to expand

Intro to Splunk (eLearning)

Aug 2026
Issued by Splunk
Splunk Using Fields certificate
Click to expand

Using Fields (Splunk)

Aug 2026
Issued by Splunk

Get in touch

Open to SOC Analyst, Security Engineering, and Blue Team internship/placement roles. For anything further, reach out directly below.

Email copied — usmankhan560026@gmail.com