- Led networking and security labs for 80+ students across TCP/IP, Linux, Wireshark, packet analysis, and troubleshooting.
- Reinforced practical SOC foundations through network visibility, protocol behavior, and hands-on analysis.
SOC Analyst · Security Engineer · Vulnerability Researcher
Chaitanya Garware
I investigate, harden, and explain security risk across SOC detection, cloud security, and application security. My strongest signal is publicly verifiable vulnerability research: 7 published GitHub Security Advisories and 4 CVE-assigned findings.
Experience
Career journey with operational security depth.
Hands-on work across security education, healthcare security readiness, detection engineering, and infrastructure analysis.
- Built SIEM dashboards and alert workflows, supported remediation of critical vulnerabilities, and improved security visibility.
- Mapped controls for ISO 27001, HITRUST, HIPAA, and SOC 2 readiness in a healthcare security context.
- Deployed and tuned Snort/Suricata IDS rules and validated vulnerabilities using Kali Linux and Nmap.
- Improved alert quality through packet analysis, traffic inspection, and security testing workflows.
Research
Published advisories, ranked by impact.
Publicly verifiable vulnerability research across SSRF, path traversal, authorization, and stored XSS classes.
ai-agent-automation — missing ownership checks in memory APIs
Missing ownership checks allowed cross-user memory read and deletion.
Fedify — incomplete SSRF mitigation / special-use IPv4 bypass
Special-use IPv4 ranges could bypass SSRF validation controls.
ai-agent-automation — workflow step path traversal
Read/write access was possible outside the expected directory boundary.
Langroid — file tool path traversal outside configured directory
Caller-controlled paths could escape the configured working directory.
All published advisories
Full list ordered by severity and recruiter impact.
| # | Advisory | Project | Severity | Impact | CVE |
|---|---|---|---|---|---|
| 1 | GHSA-qv97-83w4-ff86 | ai-agent-automation | High 8.8 | Cross-user memory read/deletion | CVE-2026-54519 |
| 2 | GHSA-xw9q-2mv6-9fr8 | fedify | High 8.6 | SSRF validation bypass | CVE-2026-50131 |
| 3 | GHSA-cm8g-8jfq-887p | ai-agent-automation | High 8.1 | Workflow path traversal | CVE-2026-54520 |
| 4 | GHSA-fg23-3346-88f5 | langroid | High 7.1 | File path traversal | CVE-2026-50181 |
| 5 | GHSA-cvpc-hccg-wmw4 | formie | Moderate 6.3 | Unauthorized config modification | — |
| 6 | GHSA-5p3m-vhh6-9236 | stigmem | Moderate 6.3 | Blind SSRF | — |
| 7 | GHSA-cwv4-h3j5-w3cf | rama | Low 3.7 | Stored XSS | — |
Projects
Selected technical work.
A focused set of projects that support the same security narrative: detection, cloud hardening, automation, and research.
OpenSOC-AI
LLM-assisted SOC research for log analysis, threat extraction, MITRE ATT&CK mapping, and structured analyst output.
AWS Cloud Security Scanner
Security automation for IAM, S3, logging, and practical cloud hardening workflows.
Vulnerability Research Lab
Patch diffing, PoC reproduction, advisory evidence packs, and disclosure writing.
Quantum Password Manager
Password security project exploring encryption, credential protection, and secure interface patterns.
Skills
Core competencies ecosystem.
Grouped by how the skills are used in real security work, not by arbitrary percentage bars.