Security engineering & assurance

Close gaps in detection and security controls.

Follow Red Team findings into selected detection and control changes: SQL Server abuse monitoring, unusual SMB probing, credential-exposure hunting and Active Directory findings. Explore EDR capability evaluation, authentication validation and the remaining engineering priorities alongside that delivered work.

UK Water Utility

Evaluate EDR against real incident-response needs

Endpoint Security & Technical Evaluation

Assessed SentinelOne investigation, containment and recovery capabilities against SOC requirements, including Sentinel/ServiceNow integration, rollback dependencies and automation licensing.

Read the story
UK Water Utility

Verify Kerberos activity after an authentication change

Active Directory & Authentication Assurance

Analysed Windows security events and confirmed Kerberos activity on all 13 servers in scope, giving the Active Directory team a clear result after NTLMv2 enforcement.

Read the story
UK Water Utility

From Red Team findings to SQL and SMB detections

Threat-Informed Detection Engineering

Built SQL Server command execution and SMB enumeration alerts, alongside credential hunting and identity hardening. Selected delivery from a broader 26-item engineering backlog.

Read the story
UK Water Utility

Extend Defender Live Response with PowerShell and KQL

Incident Response Engineering

Built live endpoint collection and command tools, persistence checks and reusable KQL investigation functions. Enabled Defender’s native Attack Disruption for automated account containment.

Read the story
Growing MSSP with Offensive Services

From external attack surface to assumed-breach testing

Offensive Scoping & Threat Modelling

I used external discovery and internal assessments to shape testing priorities around email, Active Directory, critical systems and the telemetry needed to investigate an intrusion.

Read the story
Growing MSSP with Offensive Services

When training videos expose administrator credentials

Breach investigation & client leadership

Led a data-breach investigation involving administrator credentials exposed in training videos, reviewed attacker access and handed a remediation plan to the client.

Read the story

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Ask about an investigation, a technology or my contribution. Answers link to the relevant case and technical detail.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.