A collection of accomplished threat hunts and security engineering projects built from real-world investigations. I focus on securing environments end-to-end across endpoints, infrastructure, and networks through device hardening, network segmentation, and attack surface reduction.
My approach is hands-on and practical: analyzing behavior, building detection logic, and developing repeatable playbooks. I also integrate agentic AI automation to accelerate detection, streamline investigations, and reduce response time.
- Threat Hunting & Incident Investigation
- Detection Engineering (KQL / Log Analysis)
- Device & Infrastructure Hardening
- Network Segmentation & Attack Surface Reduction
- AI-Assisted Security Automation
-
Vulnerability Management Program Implementation
End-to-end vulnerability management lifecycle with risk prioritization and remediation strategy. -
Programmatic Vulnerability Remediation (PowerShell & Bash)
Automated remediation workflows using scripting to reduce exposure and improve patching efficiency.
-
Tor Browser Usage Detection
Identifying anonymization tools through endpoint and network telemetry. -
Business Email Compromise (BEC)
Investigation of email-based attacks, attacker behavior, and detection strategies. -
Cloud VM Breach Investigation
Analysis of unauthorized access, persistence, and lateral movement in cloud environments. -
EmberForge Source Code Exfiltration
Full attack reconstruction: initial access → persistence → data staging → exfiltration.
- SIEM & Detection: Microsoft Sentinel, KQL, Log Analytics
- Endpoint & Monitoring: Wazuh, Sysmon
- Networking & Security: Wireshark, tcpdump, Nessus
- Scripting & Automation: PowerShell, Bash
- Cloud & Systems: Azure, Windows, Linux
I approach security with a structured and investigative mindset:
- Understand normal behavior
- Detect anomalies through data
- Validate with evidence (logs, queries, timelines)
- Build repeatable detection and response playbooks