Senior Security Engineer · Thales ASRT

I find how systems break—then help make them stronger.

I work across application security, offensive security, threat detection, and response. My background in the SOC shapes how I test: every attack path should lead to a better defense.

01 / Who I am

Security is more useful when you understand both sides of it.

I’m Karan, a Senior Security Engineer at Thales’ Advanced Security Response Team. I started in security operations, where I learned to investigate suspicious activity and understand the evidence an attack leaves behind. That experience pulled me toward application defense and offensive security.

Today I assess web applications, test attack techniques, build and tune defenses, and automate repetitive security work. Outside the day job, I build labs, work through practical challenges, and write down what I learn—because explaining a technique is often the fastest way to find the parts I do not yet understand.

Ask the question first Understand the risk before reaching for a tool.
Test realistically Validate how an attacker would actually move.
Leave better defenses Turn findings into detection or prevention.
Keep learning in public Document lessons, not just outcomes.

02 / Selected work

Evidence of how I approach a problem.

A small, deliberate selection of hands-on research—not an exhaustive list of every lab or writeup.

Offensive security

eCPPTv3: lessons from the assessment

A candid reflection on preparation, decision-making under pressure, and the lessons I carried into future testing.

Read the writeup →
Attack & defense

Proving Grounds labs

A curated archive of authorized lab assessments, organized by the techniques and security questions each one explores.

Browse the lab archive →

03 / My security journey

From detecting attacks to understanding how they happen.

My path is why I naturally connect offensive testing with detection and application defense.

2026 — Present

Senior Security Engineer · Thales ASRT

Advanced Security Response Team.

2024 — 2025

Security Engineer · Thales ASRT

Application defense, threat response, and security engineering.

2024

SOC Engineer · Imperva

Security operations and investigation.

2022 — 2023

Security Analyst → Senior Security Analyst · SecureOps

Detection, triage, investigation, and incident-response foundations.

2020 — 2020

Information Security & Infrastructure

City of Brampton, Microsoft, and technical-support roles that built a practical infrastructure baseline.

04 / How I think

Better security starts with better questions.

“I don’t start with the tool. I start with the question: what are we protecting, how could it fail, and what would that failure look like?”

When I assess a system

  • What is the real attack surface?
  • Which path is most likely—not merely possible?
  • What evidence would the attack leave behind?
  • Can we reproduce, detect, and reduce the risk?

05 / Currently

What has my attention right now.

Learning Advanced offensive-security techniques

Building depth through hands-on labs and applied research.

Building More repeatable security testing

Finding opportunities to automate repetitive validation and investigation work.

Exploring The application-security / purple-team space

Connecting realistic testing with controls that make defenders stronger.

07 / Tools & platforms

Tools I have used in practice.

Grouped by the security work they support, rather than presented as an unstructured wall of logos.

Offensive security

Assess, validate, and report

Kali Linux logoKali Linux
Burp Suite logoBurp Suite Pro
Metasploit logoMetasploit
NMAPNmap
TENNessus
OWASP logoOWASP ZAP

Security operations

Detect, investigate, respond

Splunk logoSplunk
CSCrowdStrike
CBCarbon Black
MSDefender
Wireshark logoWireshark

Application & network security

Protect the edge

IMPImperva WAF
IMPDDoS Protection
IMPBot Management
HTTPHTTP debugging
Wireshark logoTraffic analysis

Development & automation

Build repeatable security work

Python logoPython
Bash logoBash
Git logoGit
GitHub logoGitHub
PSPowerShell
Postman logoPostman
Docker logoDocker