A skill, applied
Threat hunting
I follow hypotheses across endpoint, identity, VPN and network evidence, using timelines and frequency analysis to investigate activity beyond the initial alert. Red Team follow-through also included hunting for cleartext credentials in files and configuration material.
Experience at UK Water Utility · Growing MSSP with Offensive Services · University in Lebanon
All cards in this section are viewed.
From Red Team findings to SQL and SMB detections
Threat-Informed Detection EngineeringBuilt SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.
Read the storyKeep the SOC running through an MDR outage
SOC Operations & MDR TransitionPreserved supplier knowledge, supported interim incident handling and built an out-of-hours escalation process when an MDR provider became unavailable. Carried those lessons into the replacement service.
Read the storyTwo compromised VPN accounts. One exposed file share.
Network & Identity Incident ResponseI traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.
Read the storyLeading SOC shifts across 150+ client environments
MSSP Security Operations & Incident ResponseI combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.
Read the storyTesting Windows telemetry in a HELK threat-hunting lab
Academic project / Threat huntingI evaluated HELK deployment and Windows logging options against simulated attacks, documenting the setup and detection results in an academic report.
Read the storyRelated skills