Skip to content
Jay Kawa

Jay Kawa

SOC AnalystSIEM, Threat Detection & DFIR

Building tools that turn hours of forensic investigation into minutes of automated response.

jay@soc:~read-only

whoami --status

status
open to opportunities
location
Pune, India (open to remote)
focus
SOC · Threat Detection · DFIR Automation

Featured work

MyFRT

My First Responder Tool

Karpuragaurai Technologies

Lead developer

A Python-based digital forensics platform that automates the full evidence lifecycle for real-world incident response — from acquisition through analysis to court-ready reporting. Built around forensic disk image processing across Windows, Linux, and macOS, including BitLocker and LUKS encrypted volumes.

Leads the development team — assigns tasks, reviews and merges code, owns architecture decisions.

the problem

Digital forensic investigations stall in the gap between acquiring evidence and being able to look at it. Analysts move between separate tools to image a disk, verify its integrity, mount it, extract artifacts, and search them — hours before anyone sees a single meaningful artifact. MyFRT collapses that into one automated pipeline.

  1. ACQUIRE
  2. PROCESS
  3. ANALYZE
  4. INDEX & SEARCH
  5. REPORT
  6. DEPLOY
ACQUIRE
Live RAM acquisition via Microsoft AVML and forensic disk imaging in E01 and RAW/DD formats — hash-verified with MD5 and SHA-256, so evidence is provably unaltered from capture onward.
PROCESS
Handles E01 and RAW/DD images across Windows, Linux, and macOS, including BitLocker and LUKS encrypted volumes, plus RAM dump analysis for Windows and Linux.
ANALYZE
Windows Event Log (EVTX) parsing directly from forensic images, YARA-based malware analysis, and password cracking with John the Ripper — artifacts surfaced without manually mounting or exporting the image first.
INDEX & SEARCH
Migrated search and storage from Elasticsearch/MongoDB to OpenSearch and CouchDB, pre-computing indexes during ingestion — near real-time search and near-instant file browsing across 100GB+ datasets.
REPORT
Enhanced HTML reporting engine generating court-ready, exportable incident reports, plus keyword-scoped exports.
DEPLOY
Packaged as a standalone Windows installer (NSIS) for deployment across analyst workstations.
stack
  • Python
  • Flask REST API
  • JWT auth + RBAC
  • OpenSearch
  • CouchDB
  • YARA
  • John the Ripper
  • NSIS

90%

reduction in incident triage time

100GB+

datasets searchable in near real-time

Other projects

Skills

SIEM & Security Analytics
  • Splunk
  • OpenSearch
  • Elastic Stack
  • Wazuh
  • Wireshark
  • Log Analysis
Threat Detection & Response
  • Incident Response
  • Threat Detection
  • Alert Triage
  • EDR
Digital Forensics (DFIR)
  • Autopsy
  • Volatility
  • EVTX Analysis
  • YARA
  • John the Ripper
  • Magnet Forensics
  • FTK Imager
Network & Vulnerability Assessment
  • Snort
  • Nmap
  • OpenVAS
Programming & Automation
  • Python
  • Bash Scripting
  • Flask
  • REST API Development
Databases
  • OpenSearch
  • CouchDB
Operating Systems
  • Linux
  • Windows
  • macOS
Offensive Security Tools
  • Metasploit
  • Burp Suite

Experience & education

  1. Karpuragaurai Technologies

    Nov 2024 — Present

    Lead Software Developer, Security Automation & DFIR Tooling

    Mumbai, India (Remote)

    Leads development of MyFRT — assigns tasks, conducts code reviews, and merges contributions across the team.

  2. University of Mumbai

    2020 — 2024

    B.E. Information Technology

    CGPA 8.1 / 10

    Cybersecurity Club Leader — led penetration testing projects using Burp Suite and Metasploit.

Certifications & training

CTF platforms
  • TryHackMe
  • picoCTF
  • OverTheWire

Cryptography, web exploitation, and Linux command-line security.

Job simulations
  • ANZ Australia
  • Mastercard
  • AIG Shields Up

Completed Oct 2023.

Get in touch

Open to SOC analyst and DFIR engineering roles, in Pune or fully remote. Email is the fastest way to reach me.