SIEM and monitoring lab
Centralized log ingestion and investigation workflows with endpoint telemetry.
I build SIEM pipelines, endpoint visibility labs, and defensive tools that make investigations faster and telemetry clearer.
Endpoint telemetry pipeline
Detection-focused dashboards
Practical investigation workflows
A few highlights. Full list lives in Projects.
Centralized log ingestion and investigation workflows with endpoint telemetry.
Small utilities that speed up blue team workflows and system visibility.
Extensions for quick lookups and investigation context during triage.
The work I enjoy and the problems I like solving.
Short technical notes, incident-style breakdowns, and build logs.
I work across offensive and defensive security, with a practical focus on visibility, detection, and investigation workflows. I like building things that are small, useful, and easy to run in real environments.