At Trellix, I build Python and VirusTotal API automation pipelines that query, download, and triage roughly 2,000 samples each month, reducing manual collection time by 70%.
I create generic detections for PE and non-PE artifacts, AMSI, macros, and Linux strings, while hunting targeted clusters and supporting daily DAT releases with over 99% on-time signature delivery.
Previously at Mindtree on Microsoft Defender/MTP, I analyzed malicious documents, PDFs, scripts, and executables, delivering high-priority customer remediation guidance in under 24 hours. I also led outbreak response and authored more than 100 PUA signatures and classification rules.
I research multi-stage infection chains, fileless malware, image steganography, and process hollowing, and have published technical research on XWorm and PureRAT.

