A skill, applied
Incident timeline reconstruction
I correlate authentication, VPN, mailbox and Windows artefact timestamps to explain how an intrusion developed and where gaps in the available evidence remain.
Experience at Growing MSSP with Offensive Services
All cards in this section are viewed.
Vishing investigation without the original EDR logs
SOC / Incident ResponseI rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.
Read the storyTwo compromised VPN accounts. One exposed file share.
Network & Identity Incident ResponseI traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.
Read the storyTracing invoice fraud through mailbox rules and MFA changes
Identity & Email Incident ResponseI reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.
Read the storyRelated skills