SOC & incident response
Investigate the intrusion
Investigate identity compromise, malware and lateral movement through EDR telemetry, Microsoft 365 audit logs, VPN sessions and Windows artefacts. Follow the evidence from alert triage to incident scoping and response.
All cards in this section are viewed.
Trace compromised VPN access into the network
Network & Identity Incident ResponseI correlated NTLM logons with VPN address assignments and network activity to scope two compromised accounts, then extended host investigation with Velociraptor.
Read the storyFollow a mailbox compromise through the account
Identity & Email Incident ResponseI reconstructed Microsoft 365 account compromise through Azure sign-in logs, Office compliance records and browser history, then investigated unauthorised MFA registration and inbox rules.
Read the storyUnpack a staged PowerShell malware chain
Malware Analysis / Incident ResponseI deobfuscated a PowerShell loader and traced MSBuild, C2 and Autorun behaviour through controlled analysis, then checked which stages appeared in client telemetry.
Read the storyReconstruct a remote-support intrusion
SOC / Incident ResponseI used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.
Read the storyRead the operation behind the OT alert
OT Security Monitoring & InvestigationInvestigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.
Read the storySOC leadership and incident response across client environments
MSSP Security Operations & Incident ResponseLed SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.
Read the storyCNI SOC leadership and investigation standards
Security Operations LeadershipOnboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.
Read the storyAutomate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storyFollow a skill into the work