Welcome to my cybersecurity portfolio. This GitHub showcases hands-on security investigations, threat hunting exercises, cloud security projects, incident response case studies, and detection engineering initiatives developed through practical learning and cyber range engagements.
- Cloud Security
- Threat Hunting & Detection Engineering
- Microsoft Sentinel
- Microsoft Defender XDR
- Azure Security
- Incident Response
- Vulnerability Management
- AI DevSecOps
- AI Governance, Risk & Compliance (AI GRC)
Investigated unauthorized TOR Browser installation and usage using Microsoft Sentinel, Defender XDR, and KQL. Identified anonymized network communications, correlated endpoint telemetry, and mapped findings to MITRE ATT&CK techniques.
Designed an AI-assisted detection and response workflow leveraging Microsoft Sentinel, KQL analytics, Python automation, and alert triage processes.
Performed ransomware incident analysis, malware investigation, timeline reconstruction, and containment assessment.
Implemented security hardening and compliance remediation activities aligned with DISA STIG requirements.
Developed an end-to-end vulnerability management engagement focused on identification, prioritization, remediation, and reporting.
Leveraged Microsoft Sentinel analytics and KQL detections to investigate identity-focused attack scenarios, including MFA bypass indicators and related tactics.
- Security Operations
- Threat Hunting
- Incident Response
- Detection Engineering
- Security Monitoring
- Cloud Security
- Microsoft Azure
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
- Microsoft Defender for Cloud
- Microsoft Sentinel
- Programming & Automation
- Kusto Query Language (KQL)
- Python
- PowerShell
- Governance & Compliance
- NIST Cybersecurity Framework (CSF)
- Security Governance
- AI Governance, Risk & Compliance (AI GRC)
- STIG Compliance
- Data Center Engineeering built Cloud Infrastructure & Applications
- SOC Operations β alert triage, L2/L3 investigation, detection engineering
- Threat Hunting β hypothesis-driven hunts, lateral movement analysis
- Zero Trust - architectures and guidelines designed to protect hybrid, multi-cloud environments
- Detection Engineering - designing, building, and maintaining logic to identify malicious activity in real-time
- Cloud Security Architecture - structural blueprint that integrates hardware, software, and operational policies to protect cloud ecosystems
- Incident Response β containment, isolation decisions, IR reporting
- Vulnerability Management β prioritization and remediation workflows
- AI Security & Governance β guardrails, deterministic decision logic, agentic AI defense
- Security Automation - the use of software-defined workflows to detect, investigate, and mitigate cyberthreats
- CompTIA Security+ (In Progress)
- Microsoft SC-200 (In Progress)
π€ Connect With Me LinkedIn: https://www.linkedin.com/in/sallie-chait-57a4893
