SANITIZED TECHNICAL WORK
Detection, investigation, and automation work.
KQL Detection & Hunting
Sanitized query cards document hunt objective, data source, detection behavior, investigation notes, false-positive considerations, and opportunities to tune logic into durable detections.
PowerShell Security Automation
Utilities for indicator enrichment, API integrations, incident parsing, normalization, and reporting — built to make manual response work repeatable without over-automating analyst decisions.
Detection Engineering
Detection logic, tuning methodology, investigation workflows, and ATT&CK mapping where appropriate. Employer-confidential queries and infrastructure remain intentionally excluded.