I build detections, not alerts — Sentinel analytics rules engineered against real telemetry, validated with dated backtests, and documented end-to-end so an analyst can actually work them.
🎯 Currently: decomposing MITRE ATT&CK one tactic at a time into complete, correlated detection suites. 🔗 Start here → detection-engineering-portfolio — the Credential Access tactic built end-to-end (12 detections across 3 tactics), with a correlation layer that fuses them into higher-confidence incidents.
What I work in
- Detection engineering — baseline-derived thresholds, seam-matched coverage, honest validation
- Microsoft Sentinel · KQL · Defender for Endpoint (
DeviceLogonEvents,DeviceProcessEvents,DeviceNetworkEvents) - MITRE ATT&CK — coverage mapping, complementary rather than duplicative detections
- Analyst playbooks — triage-to-disposition workflows written for the person on the other end of the alert
Background & growth
- Hands-on detection practice in a cyber-range lab environment, including a SOC training program
- Google Cybersecurity Certificate · working toward CompTIA Security+
- Learning in public, one validated detection at a time