How I Can Help You
Build a Detection Lab
Stand up a full threat detection lab from scratch — SIEM, EDR, SOAR — using only open-source tools.
Start the series ›Learn Threat Hunting
Hypothesis-driven hunting fundamentals — from theory to structured, repeatable hunt planning.
Start the series ›Read Security Research
Deep dives on real malware & APT case studies — Remcos, DarkHotel, REvil, and more.
Browse blogs ›Book a Talk or Training
Conference talks and hands-on trainings on threat hunting and detection engineering.
See talks ›The Security Monk
Daily cybersecurity explainer reels on Instagram & YouTube Shorts, following a first-person journey into the DART/DFIR engineer role.
Get new THOR-HQ content by email
New videos, blog posts, and hunt write-ups — straight to your inbox, no spam.
Watch My Latest Videos
Watch more ›Latest Blogs
Talks & Trainings
About Me
I currently head Security Operations and Tactical Security Functions at CRED India. I've worked as an information security professional across multiple global SOCs, building threat-hunting programs and turning them into business-as-usual practice for high-profile clients and companies — including deploying threat-hunting capability on the cloud.
I'm a security analytics enthusiast who loves coffee and automation, and I built THOR as a restriction-free way to keep studying threat hunting on my own terms — using open-source tools instead of enterprise EDR budgets I don't have.
With great powers comes greater responsibility.
FAQs
Why build this project?
Restriction-free setup to enable me to study and learn: Threat Hunting is a mythical subject, different teams do it differently and that's the beauty of it, but what doesn't change is the nature of the same sample threat that is hunted — no matter what EDR/security platform you use for hunting, malware will behave independently of your security stack, until and unless you have next-gen polymorphic customized malware code in your environment. Since I don't have enough resources and financial support to buy an enterprise EDR to study the behaviors of malware, this project is an attempt to build something from open-source technologies (a huge shout out to the open-source community for building and contributing great projects to enable people like me to independently research and study the latest security samples and threats).