Security automation
Build repeatable workflows for the SOC.
Use PowerShell, KQL and Defender Live Response for endpoint investigation and evidence collection. Explore curated Sentinel test incidents with Copilot Studio and Power Automate, agent-assisted persistence review, executive reporting and reconnaissance automation.
All cards in this section are viewed.
Extend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyGenerate Sentinel test incidents from Teams
Security Automation & Integration TestingI built a Teams workflow using Copilot Studio and Power Automate, used around seven times daily by the ServiceNow team to test Sentinel entity and incident-metadata configurations.
Read the storyAutomate Windows and Linux evidence collection
Incident Response AutomationBuilt Defender Live Response workflows that deploy an incident-response collector, run it and upload the evidence through a secured link for the retainer team.
Read the storyAutomate incident briefings that explain the follow-up
Incident Reporting & Executive CommunicationBuilt an automated executive-slide workflow that connects each incident of note to the weakness exploited and the corrective actions that need attention.
Read the storyFrom an organisation name to repeatable reconnaissance
Offensive Security AutomationI built a tool that started with an organisation name and automated reconnaissance and lightweight checks, making repeated assessment preparation reusable.
Read the storySkills used in these cases