SOC & incident response

Investigate the intrusion

Investigate identity compromise, malware and lateral movement through EDR telemetry, Microsoft 365 audit logs, VPN sessions and Windows artefacts. Follow the evidence from alert triage to incident scoping and response.

Growing MSSP with Offensive Services

Trace compromised VPN access into the network

Network & Identity Incident Response

I correlated NTLM logons with VPN address assignments and network activity to scope two compromised accounts, then extended host investigation with Velociraptor.

Read the story
Growing MSSP with Offensive Services

Follow a mailbox compromise through the account

Identity & Email Incident Response

I reconstructed Microsoft 365 account compromise through Azure sign-in logs, Office compliance records and browser history, then investigated unauthorised MFA registration and inbox rules.

Read the story
Growing MSSP with Offensive Services

Unpack a staged PowerShell malware chain

Malware Analysis / Incident Response

I deobfuscated a PowerShell loader and traced MSBuild, C2 and Autorun behaviour through controlled analysis, then checked which stages appeared in client telemetry.

Read the story
Growing MSSP with Offensive Services

Reconstruct a remote-support intrusion

SOC / Incident Response

I used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.

Read the story
UK Water Utility

Read the operation behind the OT alert

OT Security Monitoring & Investigation

Investigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.

Read the story
Growing MSSP with Offensive Services

SOC leadership and incident response across client environments

MSSP Security Operations & Incident Response

Led SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.

Read the story
UK Water Utility

CNI SOC leadership and investigation standards

Security Operations Leadership

Onboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.

Read the story
UK Water Utility

Automate endpoint investigation and response

Response Automation / Incident Response Engineering

Built PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.

Read the story
UK Water Utility

Automate evidence collection for incident-response support

Response Automation / Evidence Collection

Automated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.