Viewed
A skill, applied
Persistence analysis
I inspect running services and Run-registry entries during endpoint investigation, and analysed Autorun persistence in a staged malware sample.
Experience at UK Water Utility · Growing MSSP with Offensive Services
All cards in this section are viewed.
UK Water Utility
Extend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyGrowing MSSP with Offensive Services
From obfuscated PowerShell to MSBuild injection
Malware Analysis / Incident ResponseI unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.
Read the storyRelated skills
PowerShellKQLMicrosoft Defender for EndpointDefender Live ResponseDefender Attack DisruptionAI-assisted investigationMicrosoft Entra IDInvestigation runbooksEndpoint detection & response (EDR)Incident responseMalware analysisStatic malware analysisDynamic malware analysisProcess Monitor (Procmon)CrowdStrike