Detection Engineering & Elastic SIEM
Custom KQL detection rules, threshold-based alerting, and centralized log ingestion using Elastic Stack and Filebeat.
I build SIEM pipelines, endpoint visibility labs, and defensive tools that make investigations faster and telemetry clearer.
A few highlights. Full list lives in Projects.
Custom KQL detection rules, threshold-based alerting, and centralized log ingestion using Elastic Stack and Filebeat.
Real-time SSH and RDP brute-force detection with Slack alerting, firewall enforcement, and automated response actions.
Python-based authentication failure analysis and structured log reporting tools designed to accelerate investigation and triage.
The work I enjoy and the problems I like solving.
Short technical notes, incident-style breakdowns, and build logs.
I work across offensive and defensive security, with a practical focus on visibility, detection, and investigation workflows. I like building things that are small, useful, and easy to run in real environments.