SOC & incident response
Reconstruct the intrusion. Establish the scope.
Investigate compromised accounts, staged malware and remote-support intrusions using endpoint, identity, VPN and mailbox evidence. Follow the reasoning from the first signal to containment decisions, including investigations with missing EDR history and OT activity that needed operational context.
All cards in this section are viewed.
Vishing investigation without the original EDR logs
SOC / Incident ResponseI rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.
Read the storyTwo compromised VPN accounts. One exposed file share.
Network & Identity Incident ResponseI traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.
Read the storyTracing invoice fraud through mailbox rules and MFA changes
Identity & Email Incident ResponseI reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.
Read the storyFrom obfuscated PowerShell to MSBuild injection
Malware Analysis / Incident ResponseI unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.
Read the storyExtend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyAutomate Windows and Linux evidence collection
Incident Response AutomationBuilt Defender Live Response workflows that deploy an incident-response collector, run it and upload the evidence through a secured link for the retainer team.
Read the storyDistinguish OT backup traffic from suspicious activity
OT Monitoring & Incident InvestigationCorroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.
Read the storyLeading SOC shifts across 150+ client environments
MSSP Security Operations & Incident ResponseI combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.
Read the storyEvaluate EDR against real incident-response needs
Endpoint Security & Technical EvaluationAssessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.
Read the storyWhen training videos expose administrator credentials
Breach investigation & client leadershipLed a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.
Read the storySkills used in these cases