A skill, applied
NTLM authentication
I traced anomalous NTLM logons to compromised VPN sessions, worked on NTLMv1 findings after Red Team testing, and reviewed server-level Kerberos activity following an NTLMv2 enforcement change.
Experience at UK Water Utility · Growing MSSP with Offensive Services
All cards in this section are viewed.
From Red Team findings to SQL and SMB detections
Threat-Informed Detection EngineeringBuilt SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.
Read the storyTwo compromised VPN accounts. One exposed file share.
Network & Identity Incident ResponseI traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.
Read the storyVerify Kerberos activity after an authentication change
Active Directory & Authentication AssuranceAnalysed Windows security events and confirmed Kerberos activity on all 13 servers in scope, giving the Active Directory team a clear result after NTLMv2 enforcement.
Read the storyRelated skills