Shreya Khochare

DevOps Engineer

Hyderabad, Telangana, India6 yrs 8 mos experience
Highly Stable

Key Highlights

  • Certified GCFA professional with extensive cybersecurity experience.
  • Specializes in Ransomware and BEC investigations.
  • Proven track record in international and domestic projects.
Stackforce AI infers this person is a Cybersecurity expert specializing in Digital Forensics and Incident Response.

Contact

Skills

Core Skills

Incident ResponseCybersecurityDigital Forensics

Other Skills

AccessData FTKBECBEC InvestigationComputer ForensicsCrowdstrikeCrowdstrike EDRELK KibanaEnCase ForensicsForensic ReportsForensic Toolkit (FTK)Fraud DetectionFraud InvestigationsGoogle SuiteInsurance FraudMagnet AXIOM

About

I am a certified GCFA professional with extensive experience in cybersecurity Incident Response and Digital Forensics. As an Incident Response Lead Analyst, I manage global alerts, detect threats, and perform forensic investigations using tools like EDR, Splunk SIEM, Axiom, and EnCase Forensics. I specialize in Ransomware and Business Email Compromise (BEC) investigations, with a strong track record in both international and domestic projects. My expertise includes investigating malicious activities in Microsoft Office 365, Google Suite, and On-prem Exchange Server environments. I develop SOPs for Digital Forensics, support the SOC team, and conduct in-depth forensic analysis.

Experience

6 yrs 8 mos
Total Experience
2 yrs 2 mos
Average Tenure
2 yrs 5 mos
Current Experience

Hsbc

Incident Response Lead Analyst

Jan 2024Present · 2 yrs 5 mos · Hyderabad, Telangana, India · Hybrid

  • In HSBC, my work involves promptly responding to alerts across HSBC's global technology infrastructure, swiftly detecting, containing, and mitigating harmful events. Coordinate with the Cybersecurity Incident Management and Response Team for security incidents, using tools such as Crowdstrike EDR, Splunk SIEM, and EnCase Forensics.
  • Support and eradicate cybersecurity incidents, conducting post-incident reviews to deliver detailed root cause analyses and recommendations to improve controls and protect the bank.
  • Research on emerging threats and vulnerabilities to aid in identifying and handling cyber incidents, and support the triage of potentially malicious events to determine their severity and criticality.
  • Perform technical and forensic investigations into global cybersecurity events, identifying and mitigating cyber threats to minimize further risk to HSBC’s information assets and services. Conduct forensic services for evidence collection, processing, preservation, analysis, and presentation in support of incident investigations.
Crowdstrike EDRSplunk SIEMEnCase ForensicsIncident ResponseCybersecurity

Amazon

Security Engineer - SIRT

Oct 2022Jan 2024 · 1 yr 3 mos · Hyderabad, Telangana, India · Hybrid

  • In Amazon, I was involved in drafting Standard Operating Procedures (SOPs) for Digital Forensic processes, ensuring that our investigative methodologies are precise and efficient.
  • Worked closely with the SOC team, provided critical support in handling incident escalations. My role included determining the root cause and assessing the impact of security incidents. Lead forensic investigations, conducting comprehensive end-to-end analyses. This included in-depth analysis of Windows Operating system to identify initial compromise vectors, malicious tools/scripts, evidence of lateral movement, unauthorized access, and data exfiltration.
  • Leveraged advanced tools such as Crowdstrike to capture memory images and retrieve files from compromised hosts, enhancing our forensic capabilities. I was also responsible for preparing detailed forensic reports, providing a comprehensive documentation of our analyses and findings.
  • In response to security incidents, I was actively engaged in coordinating a cohesive response that involved multiple teams across Amazon. My focus was on providing security engineering solutions and support, with a proactive approach aimed at preventing similar incidents in the future.
  • Collaborated closely with Information Security engineers, mentoring them to improve security measures and expedite risk mitigation efforts. I actively participated in a follow-the-sun on-call rotation, providing round-the-clock support for incident response.
SOPs for Digital Forensic processesCrowdstrikeWindows Operating system analysisDigital ForensicsIncident Response

Arete

2 roles

Senior Forensic Analyst (DFIR)

Promoted

Nov 2021Oct 2022 · 11 mos · Hyderabad, Telangana, India · Remote

  • In this position, I got extensive experience as a Lead Analyst, specializing in Ransomware Investigation, Intrusion Vector, and Business Email Compromise (BEC) Investigation, across both international and domestic projects. Reported directly to the Forensic Lead/IR Lead, I consistently delivered results in critical investigations, exposing malicious activities and unauthorized data access in complex environments.
  • My expertise extended from Ransomware to BEC cases, where I meticulously gathered evidence of malicious activities and unauthorized data access through forensic analysis. I developed my skills with various Business Email Infrastructures, such as Microsoft Office 365, Google Suite, and On-prem Exchange Server, adapting to their unique forensic demands.
  • In Ransomware cases, I conducted thorough forensic triage investigation by analyzing Windows Event logs, Windows artifacts, and network firewall/anti-virus (AV) logs, swiftly identifying compromised systems within the network. For BEC investigations, I worked on Unified Audit Logs (UALs), G-Suite Audit Logs, IIS Logs, and hybrid environment-based exchange logs, unraveling the trails left by threat actors.
  • My experience on forensic tools includes ELK Kibana (THOR), SKADI, EnCase, AccessData FTK, X-Ways, Magnet AXIOM, PowerGREP, EmEditor, and SentinelOne EDR. In this position, I actively trained analysts in BEC investigation techniques, contributing to the team's growth and development.
Ransomware InvestigationBEC InvestigationMicrosoft Office 365Google SuiteOn-prem Exchange ServerDigital Forensics+1

Forensic Analyst (DFIR)

Oct 2019Nov 2021 · 2 yrs 1 mo · Hyderabad, Telangana, India · Remote

  • In this position, I was actively involved in numerous Ransomware cases within the area of Forensic Investigation. My responsibilities included conducting both triage analysis and in-depth examinations throughout these investigations.
  • Furthermore, I played a key role in preparing comprehensive Forensic Reports as part of our Forensic Engagements. In the course of my work, I leveraged a range of Forensic tools, including ELK Kibana (THOR), SKADI, EnCase, AccessData FTK, X-Ways, and Magnet AXIOM.
Ransomware casesForensic ReportsELK KibanaSKADIAccessData FTKX-Ways+2

Education

Institue of Forensic Science, Mumbai

Master of Science - MS — Digital and cyber forensics and IT security

Jan 2017Jan 2019

Institute of forensic science mumbai

Bachelor of Science — Forensic science

Jan 2014Jan 2017

Stackforce found 100+ more professionals with Incident Response & Cybersecurity

Explore similar profiles based on matching skills and experience