Viewed
Security engineering
Test the assumptions
Translate attack paths into telemetry and detection requirements, then validate security controls against observed behaviour. Explore Sentinel use-case development and Kerberos/NTLM authentication analysis.
All cards in this section are viewed.
UK Water Utility
Turn Red Team findings into engineering priorities
Security Engineering / Detection Use CasesMapped 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering items, with ATT&CK mappings and telemetry dependencies.
Read the storyUK Water Utility
From business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyUK Water Utility
Verify the behaviour behind an identity change
Identity & Security Control AssuranceAnalysed a SecurityEvent export exceeding 100 MB and confirmed Kerberos activity on all 13 servers in an NTLMv2 change review.
Read the storyFollow a skill into the work
MITRE ATT&CKDetection use-case developmentAttack-path analysisTelemetry dependenciesRisk prioritisationDetection feasibilityMDR collaborationDetection lifecycle designDetection as code designAzure DevOpsGitMicrosoft SentinelTelemetry requirementsThreat modellingTechnical governanceKQLWindows Security EventsKerberosNTLMData analysisActive DirectoryNTLMv2Authentication analysisControl assurance