eCPPTv3: lessons from the assessment
A candid reflection on preparation, decision-making under pressure, and the lessons I carried into future testing.
Read the writeup →Senior Security Engineer · Thales ASRT
I work across application security, offensive security, threat detection, and response. My background in the SOC shapes how I test: every attack path should lead to a better defense.
01 / Who I am
I’m Karan, a Senior Security Engineer at Thales’ Advanced Security Response Team. I started in security operations, where I learned to investigate suspicious activity and understand the evidence an attack leaves behind. That experience pulled me toward application defense and offensive security.
Today I assess web applications, test attack techniques, build and tune defenses, and automate repetitive security work. Outside the day job, I build labs, work through practical challenges, and write down what I learn—because explaining a technique is often the fastest way to find the parts I do not yet understand.
02 / Selected work
A small, deliberate selection of hands-on research—not an exhaustive list of every lab or writeup.
A candid reflection on preparation, decision-making under pressure, and the lessons I carried into future testing.
Read the writeup →A curated archive of authorized lab assessments, organized by the techniques and security questions each one explores.
Browse the lab archive →03 / My security journey
My path is why I naturally connect offensive testing with detection and application defense.
Advanced Security Response Team.
Application defense, threat response, and security engineering.
Security operations and investigation.
Detection, triage, investigation, and incident-response foundations.
City of Brampton, Microsoft, and technical-support roles that built a practical infrastructure baseline.
04 / How I think
When I assess a system
05 / Currently
Building depth through hands-on labs and applied research.
Finding opportunities to automate repetitive validation and investigation work.
Connecting realistic testing with controls that make defenders stronger.
06 / Credentials
Click a credential to open its public verification page.
07 / Tools & platforms
Grouped by the security work they support, rather than presented as an unstructured wall of logos.
Offensive security
Security operations
Application & network security
Development & automation