Open to collaborations
Hello, I'm Muhammad Rayhan Widayat
aka leosycthe

Detection Engineer & Security Operations Analyst

$ specialized in 

About me

Information Technology practitioner focused on blue team operation, including detection engineering, security operations, and threat hunting. Hands-on experience building end-to-end threat detection pipelines spanning Wazuh SIEM, honeypots, YARA-based detection rules, Threat Intelligence integration, and AI-assisted malware analysis, complemented by SOC Analyst L1 experience in alert monitoring and incident triage.

An offensive security (web & API pentesting, binary exploitation, reverse engineering) provides an attacker's perspective, strengthening the design of realistic, effective, and proactive detection architecture.

Experience

Blue Team Analyst May 2026 to Present
PT Cyberkarta Tugu Teknologi · Freelance / Contract
  • Designed and built an end to end malware detection pipeline with two complementary paths: one that catches malware as it is written to disk, and one that catches malware already running before monitoring came online.
  • Developed automated cross platform quarantine agents that lock down suspicious files and move them for analysis over a secured, mutually authenticated channel.
  • Automated malware triage with static behavior analysis and AI assisted summaries, enriched with threat intel reputation lookups and archived for review.
  • Validated detection efficacy with adversary emulation, and performed rule development and continuous false positive tuning to keep detection signals precise.
  • Authored incident response documentation as part of the detection system, including report templates and SOC drill runbooks based on NIST/SANS.
  • Internal engagement. Specific tools and implementation details are confidential.
Security Research Assistant Jan 2026 to Present
Network Lab UMY
  • Hardened Proxmox virtualization servers and documented the full security configuration process.
  • Monitored security alerts and system logs in real time for a production website.
  • Led internal security training for lab members.
  • Kept a research journal documenting findings and progress of the lab's cybersecurity R&D.
Security Operations Analyst L1 (Intern) Sep 2025 to Dec 2025
PT Teknologi Server Indonesia
  • Completed the 6 month Cyber Sentinel Secure training program, followed by a 3 month SOC Analyst L1 internship.
  • Monitored security alerts and system logs in real time, performing initial triage to separate false positives from real threats.
  • Documented every incident in the ticketing system per SOP and escalated confirmed threats to the L2 / Incident Response team.

Areas of Focus & Skills

SIEM
Detection Engineering & SIEM
Wazuh, SIEM rule development, Sysmon, MITRE ATT&CK, false positive tuning
HUNT
Threat Hunting & Incident Response
Threat hunting, SOC triage, NIST/SANS runbooks, ticketing & escalation
MAL
Malware Analysis & Detection
YARA rules, CAPA, static analysis, MalwareBazaar, quarantine systems
CTI
Threat Intelligence & SOAR
MISP, Shuffle, Iris, Cowrie honeypot, adversary emulation (Atomic Red Team, EICAR)
OFF
Offensive Security
Burp Suite, SQLMap, FFUF, pwntools, GDB (GEF), Ghidra, IDA Free, JADX
CTF
CTF & Security Research
HackTheBox, PicoCTF, TryHackMe · mainly pwn & reverse

Education

  • B.Sc. Information Technology
    Universitas Muhammadiyah Yogyakarta

Certifications & Training

  • CCST Networking · Cisco Aug 2024
  • SOC Level 1 · TryHackMe
  • Jr. Penetration Tester · TryHackMe
  • Web Application Pentesting · TryHackMe
  • Silver Certificate · APJC NetAcad Riders Competition 2025

Contact

Want to collab, hire, or ask about a writeup? Reach out.

Medium: @murayat99