03 / EXPERTISE

Security stack & operational capabilities.

Hands-on experience across SIEM, SOAR, EDR/XDR, incident response, network security, threat hunting and SOC delivery.

SI
SIEM & ANALYTICS

Detection & Correlation

Splunk ESMicrosoft SentinelHP ArcSightWazuhGurucul
XR
ENDPOINT / XDR

Endpoint Investigation

Trend Micro Vision OneCortex XDRCrowdStrikeSentinelOneApex One
IR
INCIDENT RESPONSE

Investigation & Containment

Malware AnalysisPhishing / BECIOC SweepsRCAThreat Hunting
AU
SOAR & AUTOMATION

Response Orchestration

Splunk PhantomSOAR WorkflowsPlaybooksResponse AutomationServiceNowClient Reporting
NW
NETWORK SECURITY

Network Telemetry

Palo AltoFortiGateIDS / IPSTippingPointFirewall Analysis
OP
SOC OPERATIONS

Frameworks & Delivery

MITRE ATT&CKSOC L1/L2/L3SLA Management
GIACGCIH
CERTIFICATION

GIAC Certified Incident Handler

Incident handling, attacker techniques, detection, containment, response and remediation.

Incident HandlingAttack TechniquesDetectionResponse
CERT / GCIH
NEXT

View investigation case studies