A skill, applied
Detection tuning & alert context
I tuned over 50 alerts and their metadata within a bank of 160 active analytics rules, relating the detection logic and alert context to real-world threat scenarios and attack paths. This work complements the over 15 detections I built and the review, testing and versioning stages of the detection lifecycle.
Experience at UK Water Utility
All cards in this section are viewed.
Turn Red Team findings into detection and hardening
Threat-Informed Detection EngineeringTurned Red Team findings into SQL and SMB detections, credential hunting and identity hardening, as part of wider work building over 15 detections and tuning over 50 alerts and their metadata.
Read the storyBuild and tune detections around real attack paths
Detection Engineering & Use-Case ManagementBuilt over 15 detections and tuned over 50 alerts and their metadata within a bank of 160 active analytics rules, connecting the work to real-world threat scenarios and attack paths.
Read the storyRelated skills