A skill, applied

Incident response

I investigate endpoint, identity, email and network incidents, establish the observed scope and support containment, eradication and recovery decisions with clients and internal teams.

Experience at Growing MSSP with Offensive Services · UK Water Utility

Growing MSSP with Offensive Services

Vishing investigation without the original EDR logs

SOC / Incident Response

I rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.

Read the story
Growing MSSP with Offensive Services

Two compromised VPN accounts. One exposed file share.

Network & Identity Incident Response

I traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.

Read the story
Growing MSSP with Offensive Services

Tracing invoice fraud through mailbox rules and MFA changes

Identity & Email Incident Response

I reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.

Read the story
Growing MSSP with Offensive Services

When training videos expose administrator credentials

Breach investigation & client leadership

Led a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.

Read the story
Growing MSSP with Offensive Services

From obfuscated PowerShell to MSBuild injection

Malware Analysis / Incident Response

I unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.

Read the story
Growing MSSP with Offensive Services

Leading SOC shifts across 150+ client environments

MSSP Security Operations & Incident Response

I combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.

Read the story
UK Water Utility

Distinguish OT backup traffic from suspicious activity

OT Monitoring & Incident Investigation

Corroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.