A skill, applied
Incident response
I investigate endpoint, identity, email and network incidents, establish the observed scope and support containment, eradication and recovery decisions with clients and internal teams.
Experience at Growing MSSP with Offensive Services · UK Water Utility
All cards in this section are viewed.
Vishing investigation without the original EDR logs
SOC / Incident ResponseI rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.
Read the storyTwo compromised VPN accounts. One exposed file share.
Network & Identity Incident ResponseI traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.
Read the storyTracing invoice fraud through mailbox rules and MFA changes
Identity & Email Incident ResponseI reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.
Read the storyWhen training videos expose administrator credentials
Breach investigation & client leadershipLed a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.
Read the storyFrom obfuscated PowerShell to MSBuild injection
Malware Analysis / Incident ResponseI unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.
Read the storyLeading SOC shifts across 150+ client environments
MSSP Security Operations & Incident ResponseI combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.
Read the storyDistinguish OT backup traffic from suspicious activity
OT Monitoring & Incident InvestigationCorroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.
Read the storyRelated skills