Usman Khan
Final-year BCA student who builds defensive security tooling instead of just studying it — SOC dashboards, threat intelligence platforms, and vulnerability scanners, all working Flask applications with real detection logic behind them.
About the analyst
I'm a final-year BCA student focused on the Blue Team side of security — monitoring, detection, and incident response, rather than offense. Most of what I've learned came from building the same kind of tooling a SOC analyst actually uses day to day, not just reading about it.
My projects follow a deliberate progression: a foundational SOC dashboard to nail the fundamentals, then a full analyst-workflow platform (SentinelX) with real threat intel integration, and a network vulnerability scanner built on Nmap. Each one is a complete Flask application — auth, database, detection logic, and reporting — not a UI mockup.
I care as much about how a tool looks and feels to the analyst using it as I do about what it detects — every dashboard here has a distinct, deliberate interface.
The tooling behind the systems
Languages
Backend & Auth
Security Tooling
Data & Reporting
Workflow
Currently deepening
Education & path
Bachelor of Computer Applications (BCA)
Final-year student, building a hands-on portfolio of defensive security applications alongside coursework to bridge the gap between theory and real SOC tooling.
Independent Security Portfolio
Self-directed build of progressively advanced Flask security platforms — SOC Dashboard → SentinelX and beyond — to demonstrate practical blue-team skills for placements.
Deployed systems
A complete Security Operations & Threat Intelligence platform simulating real analyst workflows — from raw log ingestion to alert triage, incident investigation, and executive-ready PDF reporting. Built with a navy/indigo glassmorphism interface designed for long monitoring shifts.
The foundation of the portfolio — a Security Operations Center dashboard combining a weighted organizational risk-scoring engine with a rule-based threat detection layer that auto-escalates suspicious activity as it happens.
An Nmap-powered scanner that sweeps target IPs for open ports and running services, classifies each finding by risk level against a built-in exposure database, and hands back concrete remediation steps — not just a raw port list.
Certifications
Get in touch
Open to SOC Analyst, Security Engineering, and Blue Team internship/placement roles. For anything further, reach out directly below.