About Harsh Mehta

Security systems,
made dependable.

I’m a Detection Infrastructure Engineer focused on security telemetry reliability, detection lifecycle automation, observability, threat hunting, purple teaming, and offensive research.

What I work on

I’m interested in the distance between a detection idea and a dependable security outcome: whether the telemetry exists, whether the logic holds, whether the pipeline is healthy, and whether defenders can act on the result.

Telemetry Lab is my working publication for sharing the systems, investigations, and engineering patterns that emerge from that work.

Engineering principles

Detections should be engineered, tested, observed, and maintained like production software.
Security systems should make failure visible.
Telemetry quality and operational context are as important as detection logic.
Automation should reduce repetitive work without hiding important decisions.

Capabilities

The practical disciplines and tools I use to work across the defensive and adversary perspectives.

DETECTION ENGINEERINGDetection-as-Code, detection lifecycle automation, fidelity scoring, MITRE ATT&CK mapping, and threat modelling
THREAT HUNTING & PURPLE TEAMINGAdversary emulation, coverage validation, behaviour analysis, and translating offensive findings into defensive improvements
SECURITY RELIABILITYConnector failure analysis, pipeline regression detection, alert anomaly monitoring, telemetry visibility, and signal-quality drift
LANGUAGES & TOOLINGSPL, KQL, AQL, YARA-L, Python, Bash, GitLab CI/CD, Splunk, Grafana, Docker, and Linux