Security Operations
Security Operations
My security work is centered on SOC operations, incident response, DFIR, network detection, threat hunting, and evidence-driven investigation. I focus on understanding what happened, validating the evidence, expanding scope carefully, and documenting findings in a way that supports practical response decisions.
Core focus areas
- Incident response: triage, investigation, scope expansion, IOC enrichment, containment recommendations, and incident reporting
- Network detection: PCAP analysis, DNS/HTTP traffic analysis, C2 beaconing, covert-channel investigation, Zeek, RITA, and Wireshark
- Endpoint & identity telemetry: Wazuh, Sysmon, Windows Event Logs, Sigma, Hayabusa, Active Directory lab administration, and guided Microsoft Sentinel/Splunk work
- DFIR & malware triage: Volatility 3, Procmon, Regshot, memory analysis, execution-chain reconstruction, and persistence analysis
- Threat hunting: hypothesis-driven pivots across endpoint and network evidence with MITRE ATT&CK mapping where useful
- SOC engineering mindset: telemetry validation, repeatable playbooks, evidence preservation, failure visibility, and clear operational documentation
Credentials
- GIAC Certified Incident Handler (GCIH) — 92%
- GIAC Security Essentials (GSEC) — 98%
- GIAC Foundational Cybersecurity Technologies (GFACT)
- SANS Technology Institute Applied Cybersecurity Certificate — expected November 2026
- National Cyber League, Spring 2025 — Individual Top 6%, Team Top 1.3%
Featured Security Work
SOC Investigation: HTTP Cookie Data Exfiltration
Packet-capture investigation of a covert HTTP-cookie exfiltration channel, including evidence reduction, ordered extraction, decoding, and reconstruction of stolen data.
SOC Lab: Wazuh, Sysmon & Zeek Telemetry Integration
Isolated VMware SOC lab integrating endpoint and network telemetry across Windows, Linux, Active Directory, Wazuh, Sysmon, and Zeek with validation and troubleshooting evidence.
SOC Investigation: TA505 MirrorBlast Campaign
Tier 1-style packet-capture triage used to confirm malicious activity, reconstruct network behavior, identify C2 indicators, and document investigative findings.
SEC-504: Digital Forensics & Incident Response
Full-scope simulated ransomware investigation using live triage, network analysis, memory forensics, endpoint artifacts, Sigma/Hayabusa, Zeek, and RITA to reconstruct activity and expand scope.
Security + Automation
My automation work is influenced by the same security principles: preserve evidence, separate trusted configuration from external inputs, validate before acting, make failures visible, and keep consequential actions behind explicit human approval.
For agentic systems and workflow automation, browse AI & Automation.