Response automation
Automate the repeatable
Build repeatable response workflows with PowerShell, KQL, Defender Live Response, Copilot Studio and Power Automate: endpoint investigation, evidence collection and Sentinel test incidents for ServiceNow SecOps. Explore reporting and reconnaissance automation too.
All cards in this section are viewed.
Automate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storyCreate realistic security incidents on demand
Automation / Security Operations EngineeringBuilt a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.
Read the storyTurn incident records into executive briefings
Reporting Automation / Security Operations EngineeringAutomated executive incident-of-note slides linking the security event, the weakness exploited and the follow-up actions required.
Read the storyOrganisation-led reconnaissance automation
Offensive Security AutomationI built an organisation-name-driven reconnaissance tool for discovery and lightweight checks, alongside offensive automation in Python, Bash and PowerShell.
Read the storyFollow a skill into the work