[{"content":"Eagle is an image forensics and metadata extraction tool.\nDrop an image into Eagle and it instantly extracts its EXIF data to reveal pinpoint location coordinates right where it was taken, along with all hidden EXIF metadata and camera settings in seconds.\nStack: Python · EXIF Analysis · Geolocation · OSINT · Security\nView the repository\n","date":null,"permalink":"https://shaivarth.com/projects/eagle/","section":"cool things i've built","summary":"","title":"Eagle"},{"content":"Upstream contributions to SigmaHQ/sigma, the industry standard generic signature format for SIEM detection engineering.\n#6239: CI Runtime Optimization \u0026amp; Test Suite Caching ##6239 cut Sigma\u0026rsquo;s test runtime by 5.4×, saving around 75 sec on each CI run. It was about making Sigma\u0026rsquo;s automated tests much faster.\nSigma has thousands of detection rules, and its test suite checks these rules automatically. I found that the tests were repeatedly opening and parsing the same YAML files, even when that data had already been loaded. I changed the test setup to scan the rule files once and keep the parsed data in memory so it could be reused instead of doing the same work again and again.\nA later PR by a maintainer, #6272, mentioned #6239 as an inspiration and applied similar ideas to Sigma\u0026rsquo;s regression testing. It introduced faster YAML parsing, parallel file scanning, and batched test execution.\nTogether, those changes brought the regression test runtime from roughly 4 min down to 20 sec.\n#6263: Office Autorun Keys Modification Rule Fixes #Fixed filter matching bugs in registry_set_asep_reg_keys_modification_office.yml under filter_main_known_addins:\nRemoved an accidental trailing space in \u0026lsquo;C:\\Windows\\SysWOW64\\regsvr32.exe \u0026lsquo; that caused Image|startswith to fail when matching 32-bit regsvr32.exe execution. Corrected an unintended double backslash in \\Outlook\\Addins\\OneNote.OutlookAddin so TargetObject|contains accurately matches the registry key path, preventing false positive alerts on legitimate Office add-ins. View all PRs · Sigma\n","date":null,"permalink":"https://shaivarth.com/open-source/sigma/","section":"open source","summary":"","title":"SigmaHQ / sigma"},{"content":"Xentinel is a real-time SOC simulation platform built around Python telemetry, attack detection pipelines, and live SIEM-style threat visualization.\nIt generates simulated security and authentication telemetry, processes events through detection engineering rules, and provides an interactive dashboard for SOC analyst workflows.\nStack: Python · Flask · Linux · SOC · Telemetry · SIEM · MITRE ATT\u0026amp;CK\nView the repository\n","date":null,"permalink":"https://shaivarth.com/projects/xentinel/","section":"cool things i've built","summary":"","title":"Xentinel"},{"content":"Hexora is a static malware analysis platform built with Python and FastAPI.\nIt inspects suspicious files of any format without executing them, analyzing file structures, entropy, extracted strings, and metadata to generate a comprehensive risk assessment report.\nStack: Python · FastAPI · Static Analysis · Security\nView the repository\n","date":null,"permalink":"https://shaivarth.com/projects/hexora/","section":"cool things i've built","summary":"","title":"Hexora"},{"content":"arpex is a network monitoring tool designed to detect ARP spoofing and suspicious changes in local network mappings.\nIt uses packet inspection and maintains event data so network activity can be investigated after detection.\nStack: Python · Scapy · SQLite · Networking\nView the repository\n","date":null,"permalink":"https://shaivarth.com/projects/arpex/","section":"cool things i've built","summary":"","title":"Arpex"},{"content":"Hi, I\u0026rsquo;m Sarthak. I build things in defensive security and backend engineering mostly around threat detection, packet analysis, and network telemetry. I like taking things apart, figuring out why they work, and building my own tools from the ground up.\nOutside of tech, I spend time reading philosophy, and writing down thoughts on my blog site. Feel free to reach out for a chat.\n","date":null,"permalink":"https://shaivarth.com/about/","section":" ","summary":"","title":" "},{"content":"","date":null,"permalink":"https://shaivarth.com/categories/","section":"Categories","summary":"","title":"Categories"},{"content":"A selection of security, backend, and systems projects I\u0026rsquo;ve worked on.\n","date":null,"permalink":"https://shaivarth.com/projects/","section":"cool things i've built","summary":"","title":"cool things i've built"},{"content":"this space is reserved for your company\u0026rsquo;s name. all you have to do is hire me. just saying.\n","date":null,"permalink":"https://shaivarth.com/experience/","section":"experience","summary":"","title":"experience"},{"content":"If you want to talk about a project, something you\u0026rsquo;re building, or just life, drop me a line.\n","date":null,"permalink":"https://shaivarth.com/connect/","section":"let's connect and build some cool stuff","summary":"","title":"let's connect and build some cool stuff"},{"content":"Open source projects and tools I\u0026rsquo;m contributing to.\n","date":null,"permalink":"https://shaivarth.com/open-source/","section":"open source","summary":"","title":"open source"},{"content":"I build and analyze systems to understand how they work from the wire up. Most of my work is centered around defensive security, threat detection, network monitoring, and backend engineering.\nExplore my projects or feel free to connect.\n","date":null,"permalink":"https://shaivarth.com/","section":"Sarthak Mishra","summary":"","title":"Sarthak Mishra"},{"content":"","date":null,"permalink":"https://shaivarth.com/skills/","section":"Skills","summary":"","title":"Skills"},{"content":"","date":null,"permalink":"https://shaivarth.com/tags/","section":"Tags","summary":"","title":"Tags"}]