A skill, applied

Threat hunting

I follow hypotheses across endpoint, identity, VPN and network evidence, using timelines and frequency analysis to investigate activity beyond the initial alert. Red Team follow-through also included hunting for cleartext credentials in files and configuration material.

Experience at UK Water Utility · Growing MSSP with Offensive Services · University in Lebanon

UK Water Utility

From Red Team findings to SQL and SMB detections

Threat-Informed Detection Engineering

Built SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.

Read the story
UK Water Utility

Keep the SOC running through an MDR outage

SOC Operations & MDR Transition

Preserved supplier knowledge, supported interim incident handling and built an out-of-hours escalation process when an MDR provider became unavailable. Carried those lessons into the replacement service.

Read the story
Growing MSSP with Offensive Services

Two compromised VPN accounts. One exposed file share.

Network & Identity Incident Response

I traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.

Read the story
Growing MSSP with Offensive Services

Leading SOC shifts across 150+ client environments

MSSP Security Operations & Incident Response

I combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.

Read the story
University in Lebanon

Testing Windows telemetry in a HELK threat-hunting lab

Academic project / Threat hunting

I evaluated HELK deployment and Windows logging options against simulated attacks, documenting the setup and detection results in an academic report.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.