Choose an area of work

From investigating attacks to improving defences.

Start with the role or capability you are looking for. Explore the relevant cases, then follow the tools, decisions and technical details behind them.

SOC & incident responseIncident responseEndpoint detection & response (EDR)Windows forensicsThreat hunting10 case studies Detection engineeringKQLMicrosoft Defender XDRMicrosoft SentinelMITRE ATT&CK3 case studies Security automationPowerShellDefender Live ResponsePower AutomateAI-assisted investigation5 case studies SIEM & SOAR integrationMicrosoft SentinelServiceNow SecOps / SIRCortex XSOARIntegration testing3 case studies Offensive securityThreat modellingPhysical security assessmentWeb application testingActive Directory5 case studies Security engineering & assuranceEDR capability evaluationSecurity control validationActive DirectorySQL Server security6 case studies Security leadershipSOC leadershipAnalyst coachingMDR transition & service continuityExecutive security communication5 case studies Software & production engineeringPHPMySQLLinuxAWS EC21 case study Research & academic foundationsRansomware recovery researchCryptographyHELKDigital forensics2 case studies

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.