# Rihad Roshan - Cybersecurity Researcher ## Description Rihad Roshan is a Certified Ethical Hacker (CEH) and cybersecurity researcher based in Bengaluru, India. Specializing in enterprise security automation, intelligent threat detection, SOAR/EDR implementation, and penetration testing services. ## Site https://rihadroshan.vercel.app ## Main Pages - Home: https://rihadroshan.vercel.app/ - Blog: https://rihadroshan.vercel.app/blog - Blog Archive: https://rihadroshan.vercel.app/blog/archive - RSS Feed: https://rihadroshan.vercel.app/feed.xml ## Contact - LinkedIn: https://linkedin.com/in/rihadroshan - GitHub: https://github.com/rihadroshan - Location: Bengaluru, Karnataka, India ## Expertise - Certified Ethical Hacker (CEH) - SOAR/EDR Implementation - Penetration Testing - Vulnerability Assessment - Security Automation - Threat Detection - Incident Response - Active Directory Security ## Technologies - LimaCharlie EDR - Tines SOAR - Splunk SIEM - MITRE ATT&CK Framework - Python Security Automation - Machine Learning in Cybersecurity --- # Blog Posts ## OWASP Top 10 2025 — What's New and Why It Matters **URL:** https://rihadroshan.vercel.app/blog/owasp-top10-2025 **Date:** November 8, 2025 **Author:** Rihad Roshan **Tags:** OWASP, Security, Supply Chain **Read Time:** 6 min read **Excerpt:** A comprehensive breakdown of the OWASP Top 10 (2025) updates — new categories, shifting priorities, and practical steps teams can take to improve resilience. **Content:** The 8th edition of the OWASP Top 10 2025 brings a refined focus on modern application risks. It aligns more closely with today's development practices, such as microservices, cloud-native architecture, and DevSecOps pipelines. ## What's New in OWASP Top 10 2025 The update highlights not just the presence of vulnerabilities, but the systemic flaws that lead to them. This blog explores what's new, what's changed, and why these updates matter for researchers, developers, and defenders working on secure software systems. ## Key Changes and Updates The 2025 edition introduces a sharper perspective on application security risks — reflecting both the evolution of attacker techniques and the complexity of modern ecosystems. ### Supply Chain Security Supply chain attacks have become increasingly prominent, targeting the software development lifecycle itself. The updated framework addresses these modern threat vectors. ### Cloud-Native Architecture Risks With the widespread adoption of microservices and containerization, new attack surfaces have emerged that require specialized attention. ## Implementation Guidelines Practical steps teams can take to improve their security posture and align with the updated OWASP recommendations. ### Development Team Actions Specific recommendations for development teams to integrate security into their workflows. ### Security Team Considerations Guidance for security professionals on implementing these recommendations across their organizations. --- ## Digital Arrest: The Silent Prison We Chose **URL:** https://rihadroshan.vercel.app/blog/digital-arrest **Date:** October 17, 2025 **Author:** Rihad Roshan **Tags:** Technology, Digital Minimalism **Read Time:** 5 min read **Excerpt:** We call it connection, but most of the time, it's captivity. A blog about reclaiming attention from our devices and finding pauses in a noisy world. **Content:** We talk a lot about digital security — passwords, firewalls, and two-factor authentication. But what about the most valuable asset we're losing in the digital age? Our time. Our attention. Our peace. ## The Silent Prison We Built We're not talking about the scams that try to steal your money; we're talking about the silent prison we voluntarily walked into. This new prison has no walls, no guards, and no bars. Its architecture is built from screens, notifications, and the endless scroll. ## The Illusion of Connection We call it connection, but for many of us, it's closer to constant surveillance by our own devices. Every tap, swipe, and scroll is monitored, analyzed, and optimized to keep us engaged. ### Attention as Currency Our attention has become the most valuable commodity in the digital economy. Companies compete fiercely for every second of our focus. ### The Dopamine Economy Social media platforms and apps are designed to trigger dopamine releases, creating addiction-like behaviors that keep us coming back. ## Breaking Free from Digital Arrest Reclaiming our attention and finding pauses in a noisy world requires intentional effort and strategic choices. ### Digital Minimalism Strategies Practical approaches to reducing digital overwhelm and creating space for meaningful activities. ### Mindful Technology Use Developing awareness around our device usage and creating healthy boundaries with technology. --- ## SOAR EDR: Automated Response with LimaCharlie, Tines, and Slack **URL:** https://rihadroshan.vercel.app/blog/soar-edr-automation **Date:** March 15, 2024 **Author:** Rihad Roshan **Tags:** Cybersecurity, Automation, SOAR, EDR **Read Time:** 5 min read **Excerpt:** How to build automated security workflows that detect threats, alert teams in real time, and isolate compromised systems while keeping analysts in control of critical decisions. **Content:** Cybersecurity incidents don't wait. Every second counts — and in those moments, automation can make the difference between a quick recovery and a full-blown breach. ## The Need for Automation That's what inspired me to build my own automated threat detection and response workflow, combining LimaCharlie, Tines, Slack, and Email. This project demonstrates how modern tools can work together to detect threats, alert teams in real time, and even isolate compromised systems. ## Architecture Overview The automation workflow integrates several key components to create a comprehensive security response system. ### LimaCharlie EDR Integration LimaCharlie serves as the primary endpoint detection and response platform, providing real-time monitoring and threat detection capabilities. ### Tines Workflow Orchestration Tines acts as the central orchestration engine, managing the flow between different security tools and automating response actions. ### Communication Channels Integration with Slack and email ensures that security teams are immediately notified of threats and can coordinate response efforts. ## Implementation Details Step-by-step breakdown of how to build your own automated security response system. ### Setting Up Detection Rules Configuration of detection rules in LimaCharlie to identify various threat patterns and malicious activities. ### Workflow Automation Creating automated workflows in Tines to handle different types of security incidents. ### Response Actions Automated response capabilities including system isolation, evidence collection, and team notification. ## Keeping Analysts in Control While automation handles routine tasks, critical decisions remain with human analysts to ensure appropriate response to complex threats.