Viewed
A skill, applied
SentinelOne
I reviewed SentinelOne detection, Storyline correlation, response actions and SIEM/SIR integration in an EDR evaluation. Separately, I investigated a remote-support intrusion after SentinelOne containment; the original detection logs were unavailable.
Experience at Growing MSSP with Offensive Services · UK Water Utility
All cards in this section are viewed.
Growing MSSP with Offensive Services
Vishing investigation without the original EDR logs
SOC / Incident ResponseI rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.
Read the storyUK Water Utility
Evaluate EDR against real incident-response needs
Endpoint Security & Technical EvaluationAssessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.
Read the storyRelated skills