Portfolio

Projects & Research

Selected work exploring security operations, detection, threat intelligence, security monitoring and practical cybersecurity.

Initiative2024 - PresentActive

InfoSec Stories

A long-term body of practical cybersecurity knowledge, research, analysis, projects and lessons drawn from real security operations work.

Writing & research · SIEM · Windows internals · Linux

Research2023 - PresentOngoing

Threat Hunting Research

Hypothesis-driven hunts across client environments, including research into detection bypass techniques in Active Directory and how to close those gaps.

MITRE ATT&CK · Windows Event Logs · Sysmon · Zeek · Suricata

Project2023 - PresentOngoing

Windows Event Logging / What2Log

Practical guidance on which Windows events actually matter for defenders, audit policy, Sysmon and PowerShell logging configuration for detection.

Windows Event Logs · Sysmon · PowerShell · Group Policy

Project2022 - PresentOngoing

Detection Engineering Use Cases

A structured lifecycle for SIEM detection content, from threat research and use case design through testing, tuning and measurable ATT&CK coverage.

SIEM correlation rules · MITRE ATT&CK · Sigma-style logic · AttackIQ

Research2024 - PresentOngoing

SOC Maturity Research

Research into building, measuring, and scaling highly effective security operations from the inside out.

SOC-CMM · NRB CRG · ISO 27001 · Metrics & reporting · Process design