SOC & incident response

Reconstruct the intrusion. Establish the scope.

Investigate compromised accounts, staged malware and remote-support intrusions using endpoint, identity, VPN and mailbox evidence. Follow the reasoning from the first signal to containment decisions, including investigations with missing EDR history and OT activity that needed operational context.

Growing MSSP with Offensive Services

Vishing investigation without the original EDR logs

SOC / Incident Response

I rebuilt the timeline from Prefetch and Quick Assist artefacts, connecting a NetSupport intrusion to a spam flood and a fake IT-support call.

Read the story
Growing MSSP with Offensive Services

Two compromised VPN accounts. One exposed file share.

Network & Identity Incident Response

I traced suspicious NTLM logons through months of VPN history, scoped two compromised accounts and identified unauthenticated access to a sensitive share.

Read the story
Growing MSSP with Offensive Services

Tracing invoice fraud through mailbox rules and MFA changes

Identity & Email Incident Response

I reconstructed a Microsoft 365 mailbox compromise behind a fraudulent invoice, tracing phishing interaction, unauthorised MFA registration and inbox rules used to conceal activity.

Read the story
Growing MSSP with Offensive Services

From obfuscated PowerShell to MSBuild injection

Malware Analysis / Incident Response

I unpacked a staged loader to explain its MSBuild injection, C2 and registry persistence, then checked which behaviours had occurred on the affected endpoint.

Read the story
UK Water Utility

Extend Defender Live Response with PowerShell and KQL

Incident Response Engineering

Built live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.

Read the story
UK Water Utility

Automate Windows and Linux evidence collection

Incident Response Automation

Built Defender Live Response workflows that deploy an incident-response collector, run it and upload the evidence through a secured link for the retainer team.

Read the story
UK Water Utility

Distinguish OT backup traffic from suspicious activity

OT Monitoring & Incident Investigation

Corroborated five OT alerts against known backup behaviour and closed them as false positives. Contributed telemetry and response-ownership requirements for Claroty and Sentinel monitoring.

Read the story
Growing MSSP with Offensive Services

Leading SOC shifts across 150+ client environments

MSSP Security Operations & Incident Response

I combined SOC shift leadership with hands-on incident response in a seven-person team, within a service monitoring 70,000+ endpoints across 150+ organisations.

Read the story
UK Water Utility

Evaluate EDR against real incident-response needs

Endpoint Security & Technical Evaluation

Assessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.

Read the story
Growing MSSP with Offensive Services

When training videos expose administrator credentials

Breach investigation & client leadership

Led a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.