Skip to content
View Bard-F-Portfolio's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report Bard-F-Portfolio

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Bard-F-Portfolio/README.md

Bard Foster — Detection Engineer

I build detections, not alerts — Sentinel analytics rules engineered against real telemetry, validated with dated backtests, and documented end-to-end so an analyst can actually work them.

🎯 Currently: decomposing MITRE ATT&CK one tactic at a time into complete, correlated detection suites. 🔗 Start here → detection-engineering-portfolio — the Credential Access tactic built end-to-end (12 detections across 3 tactics), with a correlation layer that fuses them into higher-confidence incidents.

What I work in

  • Detection engineering — baseline-derived thresholds, seam-matched coverage, honest validation
  • Microsoft Sentinel · KQL · Defender for Endpoint (DeviceLogonEvents, DeviceProcessEvents, DeviceNetworkEvents)
  • MITRE ATT&CK — coverage mapping, complementary rather than duplicative detections
  • Analyst playbooks — triage-to-disposition workflows written for the person on the other end of the alert

Background & growth

  • Hands-on detection practice in a cyber-range lab environment, including a SOC training program
  • Google Cybersecurity Certificate · working toward CompTIA Security+
  • Learning in public, one validated detection at a time

📫 LinkedIn

Pinned Loading

  1. detection-engineering-portfolio detection-engineering-portfolio Public

    Systematic detection engineering on MITRE ATT&CK — the Credential Access tactic decomposed into a full detection suite plus a correlation layer, with range-proving builds in Execution and C2. Micro…

    HTML

  2. threat-hunting-portfolio threat-hunting-portfolio Public

    Hypothesis-driven threat hunts in Microsoft Sentinel / KQL, mapped to MITRE ATT&CK.