Detection engineering
Turn attack behaviour into testable detection work.
Connect business threats and Red Team findings to MITRE ATT&CK, telemetry requirements and KQL detections. Explore deployed SQL Server command-shell and SMB enumeration alerts, a governed Sentinel workflow and the wider prioritised engineering backlog.
All cards in this section are viewed.
From Red Team findings to SQL and SMB detections
Threat-Informed Detection EngineeringBuilt SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.
Read the storyGive Sentinel detections a path from threat to testing
Detection Engineering & Use-Case ManagementBuilt a staged workflow for Sentinel detections and tuning, with KQL review, named owners and post-release testing. Co-developed the wider model connecting threat scenarios, telemetry and detection coverage.
Read the storyTesting Windows telemetry in a HELK threat-hunting lab
Academic project / Threat huntingI evaluated HELK deployment and Windows logging options against simulated attacks, documenting the setup and detection results in an academic report.
Read the storySkills used in these cases