Security engineering & assurance
Close gaps in detection and security controls.
Follow Red Team findings into selected detection and control changes: SQL Server abuse monitoring, unusual SMB probing, credential-exposure hunting and Active Directory findings. Explore EDR capability evaluation, authentication validation and the remaining engineering priorities alongside that delivered work.
All cards in this section are viewed.
Evaluate EDR against real incident-response needs
Endpoint Security & Technical EvaluationAssessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.
Read the storyVerify Kerberos activity after an authentication change
Active Directory & Authentication AssuranceAnalysed Windows security events and confirmed Kerberos activity on all 13 servers in scope, giving the Active Directory team a clear result after NTLMv2 enforcement.
Read the storyFrom Red Team findings to SQL and SMB detections
Threat-Informed Detection EngineeringBuilt SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.
Read the storyExtend Defender Live Response with PowerShell and KQL
Incident Response EngineeringBuilt live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.
Read the storyFrom external attack surface to assumed-breach testing
Offensive Scoping & Threat ModellingI used external discovery and internal assessments to shape testing priorities around email, Active Directory, critical systems and the telemetry needed to investigate an intrusion.
Read the storyWhen training videos expose administrator credentials
Breach investigation & client leadershipLed a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.
Read the storySkills used in these cases