Investigations, engineering & assessments

The problem. The investigation. The result.

Trace an intrusion, inspect a Defender automation or follow a security assessment. Each case explains the problem, my contribution and the evidence behind the result, with technical detail when you want it.

26 case stories

UK Water Utility

Extend Defender Live Response with PowerShell and KQL

Incident Response Engineering

Built live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.

Read the story
Growing MSSP with Offensive Services

Vishing investigation without the original EDR logs

SOC / Incident Response

I rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.

Read the story
UK Water Utility

From Red Team findings to SQL and SMB detections

Threat-Informed Detection Engineering

Built SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.

Read the story
UK Water Utility

Generate Sentinel test incidents from Teams

Security Automation & Integration Testing

Built a Copilot Studio and Power Automate workflow that gives ServiceNow developers repeatable Sentinel incidents on demand, with curated entities, overlap protection and automatic rule reset.

Read the story
UK Water Utility

Keep the SOC running through an MDR outage

SOC Operations & MDR Transition

Preserved supplier knowledge, supported interim incident handling and built an out-of-hours escalation process when an MDR provider became unavailable. Carried those lessons into the replacement service.

Read the story
Growing MSSP with Offensive Services

Guest data exposure and authenticated internal access

Physical Security Assessment

Across assessments, we exposed guest data through weak Wi-Fi segmentation, demonstrated employee QR-code interaction and gained authenticated internal access.

Read the story
UK Water Utility

Make Sentinel and ServiceNow agree on incident closure

SIEM/SOAR Integration & Acceptance Testing

Designed and passed nine bidirectional closure tests, while defining how entities, ATT&CK context and escalation should move across Sentinel, ServiceNow SIR and XSOAR.

Read the story
Growing MSSP with Offensive Services

Two compromised VPN accounts. One exposed file share.

Network & Identity Incident Response

I traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.

Read the story
Growing MSSP with Offensive Services

Tracing invoice fraud through mailbox rules and MFA changes

Identity & Email Incident Response

I reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.

Read the story
Growing MSSP with Offensive Services

When training videos expose administrator credentials

Breach investigation & client leadership

Led a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.

Read the story
Growing MSSP with Offensive Services

From obfuscated PowerShell to MSBuild injection

Malware Analysis / Incident Response

I unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.

Read the story
UK Water Utility

Give Sentinel detections a path from threat to testing

Detection Engineering & Use-Case Management

Built a staged workflow for Sentinel detections and tuning, with KQL review, named owners and post-release testing. Co-developed the wider model connecting threat scenarios, telemetry and detection coverage.

Read the story
Growing MSSP with Offensive Services

Leading SOC shifts across 150+ client environments

MSSP Security Operations & Incident Response

I combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.

Read the story
UK Water Utility

Onboard six SOC colleagues and strengthen investigation practice

SOC Leadership & Analyst Development

Supported six hires, onboarded all six, and introduced investigation review criteria. Taught practical AiTM, NAT and identity-attack analysis while providing management cover.

Read the story
Growing MSSP with Offensive Services

Technical oversight of 50+ monthly offensive engagements

Offensive Security Leadership

I oversaw a team portfolio of more than fifty offensive engagements per month, reviewing technical delivery and reports while helping clients act on the findings.

Read the story
Growing MSSP with Offensive Services

Testing application exposure and restricted Windows environments

Offensive Security Assessment

I assessed applications, Active Directory and infrastructure, and developed payload approaches for restricted Windows environments.

Read the story
Growing MSSP with Offensive Services

From external attack surface to assumed-breach testing

Offensive Scoping & Threat Modelling

I used external discovery and internal assessments to shape testing priorities around email, Active Directory, critical systems and the telemetry needed to investigate an intrusion.

Read the story
Growing MSSP with Offensive Services

From an organisation name to repeatable reconnaissance

Offensive Security Automation

I built a tool that started with an organisation name and automated reconnaissance and lightweight checks, making repeated assessment preparation reusable.

Read the story
UK Water Utility

Distinguish OT backup traffic from suspicious activity

OT Monitoring & Incident Investigation

Corroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.

Read the story
UK Water Utility

Verify Kerberos activity after an authentication change

Active Directory & Authentication Assurance

Analysed Windows security events and confirmed Kerberos activity on all 13 servers in scope, giving the Active Directory team a clear result after NTLMv2 enforcement.

Read the story
Digital Publishing Technology Company

Keeping publishing platforms maintainable through change

Software Development & Operations

I maintained PHP/MySQL publishing applications, scripted Craft CMS migrations and documented inherited code so production support and developer handovers could continue.

Read the story
UK University / University in Lebanon

Two full scholarships. Two degrees with Distinction.

Academic Achievement & Community Leadership

I completed a Computer Science BSc and Information Security MSc with full scholarships and Distinction, alongside ransomware recovery research, a Philosophy minor and community teaching.

Read the story
UK Water Utility

Automate Windows and Linux evidence collection

Incident Response Automation

Built Defender Live Response workflows that deploy an incident-response collector, run it and upload the evidence through a secured link for the retainer team.

Read the story
UK Water Utility

Automate incident briefings that explain the follow-up

Incident Reporting & Executive Communication

Built an automated executive-slide workflow that connects each incident of note to the weakness exploited and the corrective actions that need attention.

Read the story
UK Water Utility

Evaluate EDR against real incident-response needs

Endpoint Security & Technical Evaluation

Assessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.

Read the story
University in Lebanon

Testing Windows telemetry in a HELK threat-hunting lab

Academic project / Threat hunting

I evaluated HELK deployment and Windows logging options against simulated attacks, documenting the setup and detection results in an academic report.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.