Security engineer focused on detection and practical tooling

I build SIEM pipelines, endpoint visibility labs, and defensive tools that make investigations faster and telemetry clearer.

  • Elastic
  • Sysmon
  • Winlogbeat
  • Python
  • Linux
  • Wireshark
Elastic Security – Active Detection Rules
Elastic Security dashboard showing open alerts by rule

Featured work

A few highlights. Full list lives in Projects.

Elastic SIEM detection rule with threshold logic for SSH brute force activity

Detection Engineering & Elastic SIEM

Custom KQL detection rules, threshold-based alerting, and centralized log ingestion using Elastic Stack and Filebeat.

Elastic KQL Filebeat
Slack security alert showing SSH and RDP brute-force detection with automated IP blocking and user lockout

Automated Detection & Response Workflows

Real-time SSH and RDP brute-force detection with Slack alerting, firewall enforcement, and automated response actions.

Elastic Slack Automation
Python-based authentication failure detection tool parsing Linux auth.log and generating structured security report

Custom Log Analysis & Blue Team Utilities

Python-based authentication failure analysis and structured log reporting tools designed to accelerate investigation and triage.

Python Linux Log Analysis

Core focus areas

The work I enjoy and the problems I like solving.

Detection and investigation

  • Telemetry-first thinking
  • Alert logic and triage workflows
  • Hunting and incident response support

Security tooling

  • Python automation for blue team workflows
  • Fast investigation helpers and scripts
  • Practical, repeatable lab setups

Hardening and research

  • System hardening and baseline checks
  • Threat modeling and risk-oriented fixes
  • Writeups with clear takeaways

About

I work across offensive and defensive security, with a practical focus on visibility, detection, and investigation workflows. I like building things that are small, useful, and easy to run in real environments.

  • Penetration testing and system security foundations
  • Threat hunting, incident response support, and forensic mindset
  • Tooling that speeds up SOC and investigation workflows

Contact

Best way to reach me is GitHub or LinkedIn.