Detection Engineer · Threat Hunter · Senior Security Specialist
I am a cybersecurity professional with 6+ years of experience across SOC operations, detection engineering, and Purple Team activities. I focus on turning endpoint, network, and SIEM telemetry into actionable detections and repeatable investigation workflows.
My work includes advanced alert investigation, security use-case development, log-source integration, parser engineering, detection tuning, threat hunting, and adversary-informed validation.
An open-source Linux threat hunting framework designed to support structured, evidence-driven investigations with Velociraptor.
- 114 custom Velociraptor artifacts
- 14 investigation domains covering baseline, identity, authentication, processes, network activity, persistence, file activity, privilege escalation, malware, containers, exfiltration, and secrets
- Master-triage and hypothesis-driven investigation workflow
- Repository validation with GitHub Actions
- Versioned artifact pack and implementation documentation
View the repository · Download v0.1.0
| Area | Experience |
|---|---|
| Detection Engineering | Detection lifecycle, use-case design, rule tuning, false-positive analysis, and MITRE ATT&CK mapping |
| Threat Hunting & DFIR | Hypothesis-driven hunting, triage, evidence correlation, Linux investigations, and Velociraptor |
| SOC & SIEM | Advanced alert investigation, log-source onboarding, parser development, and operational detection content |
| Purple Team | Adversary simulation support, telemetry validation, detection testing, and coverage improvement |
| Endpoint & Network Telemetry | Windows and Linux logs, Sysmon, EDR/XDR telemetry, Zeek, and network evidence |
| Automation | Python, PowerShell, Bash, Ansible, and CI-based validation workflows |
- Cloud detection engineering with KQL and Microsoft Sentinel
- Detection-as-Code workflows and CI/CD validation
- Linux threat hunting and DFIR automation
- Building practical, documented, and reusable defensive security projects
I am interested in international opportunities as a Detection Engineer, Threat Hunter, Senior SOC Analyst, or Purple Team Specialist, including roles offering relocation support.
I also welcome collaboration on detection engineering, threat hunting, Velociraptor, SIEM content, and open-source defensive security projects.