DFIR · SOC · Threat Hunting · AI-Augmented IR

DhirenBhardwaj

Senior DFIR Analyst @ AT&T

11+ years of Digital Forensics & Incident Response across AT&T, Kotak Mahindra Bank, Microsoft and Deloitte — from raw disk images to global cloud incidents. Now building the tools that let AI carry the repetitive weight of the SOC.

  • Jaipur, IN
  • Senior DFIR Analyst @ AT&T
  • EnCE · M.S. Digital Forensics
case-file — dhiren.log
0+Years DFIR & SOC
0Orgs — BFSI → BigTech
0%SLA gain @ Microsoft
0AI security tools built

01 — About

Evidence first. Everything else follows.

I've run investigations from raw disk images in a forensics lab to global cloud incident response at Microsoft to L3/L4 insider-threat cases inside a regulated bank — and now lead DFIR at AT&T: phishing, malware outbreaks, unauthorized access, suspicious network activity, with chain of custody intact.

The through-line is end-to-end ownership: detection → triage → containment → forensics → root cause → the uncomfortable meeting with leadership → the runbook that makes sure it never takes that long again.

Current obsession: AI-augmented incident response. Four working tools below — LLM-driven email triage, malware intelligence notes, memory-forensics analysis and an agent-callable investigation lab — because the future SOC has an AI analyst on shift, and someone with 11 years of incident scars should be the one training it.

I write about the field at Digital Forensic Forest.

02 — Experience

Eleven years of incident bridges.

  1. Senior DFIR Analyst

    Current

    AT&THyderabadMar 2026 — Present

    • Lead DFIR investigations across phishing, malware outbreaks, insider threats, unauthorized access and suspicious network activity.
    • Coordinate end-to-end incident management — investigation, containment, eradication, recovery, post-incident analysis.
    • Forensics across endpoints, servers, memory artifacts and cloud environments with chain-of-custody discipline.
  2. Deputy Vice President — SOC & IR Lead

    Kotak Mahindra BankMumbaiFeb 2024 — Feb 2026

    • Led L2/L3 SOC investigations — phishing, insider threat, malware, endpoint anomalies — in a regulated banking environment.
    • Forensics across email compromise and insider misuse; escalated high-severity incidents to leadership with clear impact and remediation.
    • Authored IR runbooks, ran tabletop exercises, mentored SOC analysts; aligned ops with NIST CSF & MITRE ATT&CK.
  3. Security Engineer II — Global Security Operations

    MicrosoftHyderabadJan 2022 — Jan 2024

    • Global IR coordination on Sentinel, Defender, MCAS and O365.
    • Shipped IR automation → 25% SLA improvement; automated workflows cutting manual effort by 50%.
    • KQL-driven investigations correlating events and threat intel across cloud and enterprise estates.
  4. Assistant Manager — Digital Forensics & Cyber Investigations

    DeloitteGurgaonNov 2017 — Jan 2022

    • Forensic engagements for enterprise & financial-services clients: memory forensics, endpoint investigation, email analysis, log correlation.
    • Built ELK-based log analysis platforms for threat visibility and hunting; presented findings to client leadership.
  5. Digital Forensic Analyst

    Mahindra Special Services GroupMumbaiFeb 2016 — Oct 2017

    • Cyber fraud & insider threat investigations — artifact analysis, email headers, user activity reconstruction; evidence handling with legal & compliance.
  6. Digital Forensic Analyst

    eSF LabsHyderabadJul 2014 — Feb 2016

    • Forensic imaging, RAM dump analysis, malware & web-attack investigations, Android/mobile forensics; wrote lab automation scripts.

03 — Selected Work

The AI security arsenal.

Open-source and personal R&D — every tool exists because a repetitive SOC/DFIR task annoyed me enough to automate it.

AI-Native DFIR Investigation Lab — MCP Server

Release pending

A SOC-in-a-box: a simulated enterprise security environment plus a Model Context Protocol (MCP) server that lets an AI agent run real investigations against it — the architecture pattern behind next-generation AI-assisted SOC tooling.

  • Simulated SIEM in SQLite — sign-in logs, user directory, incidents, alerts and IP threat-intel tables mirroring Azure AD / Sentinel / Defender schemas.
  • Five seeded attack scenarios: AiTM impossible travel (T1078), password spray (T1110.003), brute force (T1110.001), suspicious app access (T1528) + clean baselines.
  • Seven agent-callable investigation tools — investigate_user, enrich_ip, hunt_suspicious, incident & alert queries.
  • Doubles as a DFIR training range with verdicts and MITRE technique mapping.
  • Python
  • MCP
  • SQLite
  • MITRE ATT&CK
  • AI Agents

Source publishing soon — walkthrough on request

AI-SOC Email Triage & Forensics

Open source

Turns suspicious-email triage — the SOC's highest-volume grunt work — into a safe, repeatable, AI-assisted pipeline.

  • Parses .eml files: headers, bodies, attachments → structured JSON for case documentation.
  • Attachments stored Base64 — never executed; forensically safe by design.
  • Gemini analysis flags phishing lures, impersonation and header anomalies.
  • Python
  • Gemini
  • Email Forensics
  • Phishing
View source

MalNote — Intelligent Malware Note Generator

Open source

Automated malware triage: one file in, a complete intelligence-enriched DFIR note out.

  • SHA-256 hashing + local ClamAV scan, then correlation across VirusTotal, AlienVault OTX, ThreatFox & MalwareBazaar.
  • Auto-generates a Markdown analysis note ready for case files.
  • Optional Gemini AI layer summarises findings and recommends next DFIR actions.
  • Python
  • ClamAV
  • VirusTotal
  • Threat Intel
  • Gemini
View source

Volatility Output Analysis using AI

Open source

Memory forensics produces walls of process listings and handles — this pipes Volatility framework output through AI analysis so the anomalies surface themselves.

  • Takes raw RAM-analysis output from Volatility and applies LLM reasoning to highlight suspicious processes and artifacts.
  • Compresses hours of manual memory-dump review into a guided starting point for the examiner.
  • Python
  • Volatility
  • RAM Forensics
  • AI
View source

Digital Forensic Forest

Live

Long-running blog on digital forensics and incident response — investigation techniques, tooling notes and lessons from more than a decade in the field.

  • DFIR
  • Forensics
  • Field Notes
View source

04 — Capabilities

Proficiency earned in production incidents.

Incident Response

End-to-end DFIR
Threat Hunting
Malware Analysis
Breach Investigation
Root Cause Analysis
Insider Threat
Threat Intelligence

SIEM & Detection

Microsoft Sentinel
KQL
Splunk
ELK
Defender / MCAS
EDR / XDR
Sigma
Network Traffic Analysis

Forensics Toolchain

EnCase
Volatility
FTK
Magnet Axiom
Cellebrite
Oxygen
X-Ways
SIFT
Redline
Intella

Frameworks

MITRE ATT&CK
Cyber Kill Chain
NIST CSF
NIST IR Lifecycle
Purple Teaming
Forensic Readiness

Cloud & Platform

Azure
O365
AWS
Windows
Linux
Active Directory
Cloud Forensics

Automation & AI

Python
AI-Augmented IR
KQL
PowerShell
LLM Enrichment
MCP Agent Tooling
Triage Automation

05 — Credentials

Papers, verified.

M.S. — Digital Forensics & Information Assurance

Gujarat Forensic Sciences University

2012–14

B.Tech — Computer Science

Poornima College of Engineering

2006–10

EnCase Certified Examiner (EnCE)

OpenText / Guidance Software

2020–23

Azure Fundamentals (AZ-900)

Microsoft

2023

Security, Compliance & Identity (SC-900)

Microsoft

2023

ACE + Intella Basic & Advanced

AccessData · Vound Software

06 — FAQ

Frequently asked.

A Digital Forensics & Incident Response (DFIR) and SOC leader from India with 11+ years of experience — currently Senior DFIR Analyst at AT&T; previously Deputy Vice President (SOC & IR Lead) at Kotak Mahindra Bank, Security Engineer II at Microsoft Global Security Operations, and Assistant Manager for Digital Forensics at Deloitte. M.S. in Digital Forensics (GFSU), EnCase Certified Examiner.

07 — Contact

Establish connection.

DFIR leadership · IR transformation · cloud-native security · purple teaming strategy. Response time under 24 hours.