Viewed
A skill, applied
Microsoft Entra ID
I query Entra ID, formerly Azure AD, sign-in activity for investigation context and correlate identity changes with Microsoft 365 account compromise and Defender response actions.
Experience at UK Water Utility · Growing MSSP with Offensive Services
All cards in this section are viewed.
UK Water Utility
Extend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyGrowing MSSP with Offensive Services
Tracing invoice fraud through mailbox rules and MFA changes
Identity & Email Incident ResponseI reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.
Read the storyRelated skills
PowerShellKQLMicrosoft Defender for EndpointDefender Live ResponseDefender Attack DisruptionPersistence analysisAI-assisted investigationInvestigation runbooksEndpoint detection & response (EDR)Incident responseIncident timeline reconstructionMicrosoft 365Mailbox audit & inbox-rule analysisMFA investigationDigital forensicsAuthentication analysis