The case library

Find the work that matters to you.

Explore incident investigations, KQL and Sentinel engineering, Defender response tooling, ServiceNow integrations and offensive assessments. Follow a case into its methods, evidence and technical decisions.

23 case stories

Growing MSSP with Offensive Services

Trace compromised VPN access into the network

Network & Identity Incident Response

I correlated NTLM logons with VPN address assignments and network activity to scope two compromised accounts, then extended host investigation with Velociraptor.

Read the story
Growing MSSP with Offensive Services

Follow a mailbox compromise through the account

Identity & Email Incident Response

I reconstructed Microsoft 365 account compromise through Azure sign-in logs, Office compliance records and browser history, then investigated unauthorised MFA registration and inbox rules.

Read the story
Growing MSSP with Offensive Services

Unpack a staged PowerShell malware chain

Malware Analysis / Incident Response

I deobfuscated a PowerShell loader and traced MSBuild, C2 and Autorun behaviour through controlled analysis, then checked which stages appeared in client telemetry.

Read the story
Growing MSSP with Offensive Services

Reconstruct a remote-support intrusion

SOC / Incident Response

I used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.

Read the story
UK Water Utility

Keeping response operational through an MDR transition

SOC Continuity & Service Leadership

Led SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.

Read the story
UK Water Utility

From business risk to detection

Detection Engineering / Detection as Code

Built a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.

Read the story
UK Water Utility

Turn Red Team findings into engineering priorities

Security Engineering / Detection Use Cases

Mapped 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering items, with ATT&CK mappings and telemetry dependencies.

Read the story
UK Water Utility

Automate endpoint investigation and response

Response Automation / Incident Response Engineering

Built PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.

Read the story
UK Water Utility

Create realistic security incidents on demand

Automation / Security Operations Engineering

Built a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.

Read the story
Growing MSSP with Offensive Services

SOC leadership and incident response across client environments

MSSP Security Operations & Incident Response

Led SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.

Read the story
UK Water Utility

CNI SOC leadership and investigation standards

Security Operations Leadership

Onboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.

Read the story
Growing MSSP with Offensive Services

Technical oversight of an offensive security service

Offensive Security Leadership

Oversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.

Read the story
Growing MSSP with Offensive Services

Hands-on application and infrastructure testing

Offensive Security Assessment

I delivered application, Active Directory and infrastructure assessments, with source-code review, simulated phishing and payload work using LOLBins and DLL hijacking.

Read the story
Growing MSSP with Offensive Services

Scoping assessments around the client's threats

Offensive Scoping & Threat Modelling

I scoped external, internal and assumed-breach assessments around attack-surface discovery, Active Directory, email defences and EDR/network visibility, informed by incident-response work.

Read the story
Growing MSSP with Offensive Services

Test physical and network boundaries at client workplaces

Physical Security Assessment

I tested hotel guest/TV network segmentation, restricted-area access and employee QR scenarios, including Raspberry Pi placement tests for a controlled C2 connection.

Read the story
Growing MSSP with Offensive Services

Organisation-led reconnaissance automation

Offensive Security Automation

I built an organisation-name-driven reconnaissance tool for discovery and lightweight checks, alongside offensive automation in Python, Bash and PowerShell.

Read the story
UK Water Utility

Keep incident meaning intact across platforms

Security Operations Engineering

Validated nine bidirectional Sentinel–ServiceNow closure scenarios and defined incident, entity and escalation requirements across the SIEM/SOAR workflow.

Read the story
UK Water Utility

Read the operation behind the OT alert

OT Security Monitoring & Investigation

Investigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.

Read the story
UK Water Utility

Verify the behaviour behind an identity change

Identity & Security Control Assurance

Analysed a SecurityEvent export exceeding 100 MB and confirmed Kerberos activity on all 13 servers in an NTLMv2 change review.

Read the story
Digital Publishing Technology Company

PHP publishing platforms, migrations and production support

Software Development & Operations

Maintained PHP/MySQL publishing applications on Linux, developed Craft CMS data migrations and supported WordPress workflows, production troubleshooting and developer handover.

Read the story
UK University / University in Lebanon

Fully funded study. Distinction in both degrees.

Academic Achievement & Community Leadership

Completed a fully funded BSc and MSc with Distinction, combining specialist security study with research into ransomware key management, a Philosophy minor and community leadership.

Read the story
UK Water Utility

Automate evidence collection for incident-response support

Response Automation / Evidence Collection

Automated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.

Read the story
UK Water Utility

Turn incident records into executive briefings

Reporting Automation / Security Operations Engineering

Automated executive incident-of-note slides linking the security event, the weakness exploited and the follow-up actions required.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.