A skill, applied
Telemetry requirements
I define the logs, attribution, identity and endpoint context an investigation or detection needs, including cloud, on-premises and OT monitoring dependencies.
Experience at UK Water Utility
All cards in this section are viewed.
From Red Team findings to SQL and SMB detections
Threat-Informed Detection EngineeringBuilt SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.
Read the storyGive Sentinel detections a path from threat to testing
Detection Engineering & Use-Case ManagementBuilt a staged workflow for Sentinel detections and tuning, with KQL review, named owners and post-release testing. Co-developed the wider model connecting threat scenarios, telemetry and detection coverage.
Read the storyDistinguish OT backup traffic from suspicious activity
OT Monitoring & Incident InvestigationCorroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.
Read the storyRelated skills