A skill, applied
Endpoint detection & response (EDR)
I investigate endpoint telemetry and protection outcomes, use Defender Live Response for collection, and include EDR visibility in assessment and response planning.
Experience at UK Water Utility · Growing MSSP with Offensive Services
All cards in this section are viewed.
Extend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyVishing investigation without the original EDR logs
SOC / Incident ResponseI rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.
Read the storyFrom obfuscated PowerShell to MSBuild injection
Malware Analysis / Incident ResponseI unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.
Read the storyFrom external attack surface to assumed-breach testing
Offensive Scoping & Threat ModellingI used external discovery and internal assessments to shape testing priorities around email, Active Directory, critical systems and the telemetry needed to investigate an intrusion.
Read the storyEvaluate EDR against real incident-response needs
Endpoint Security & Technical EvaluationAssessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.
Read the storyRelated skills