A collection of investigations, security engineering projects, and hands-on research.
An external operator reused a leaked personal-email password to log into a corporate RDP account, enumerated HR file shares, and staged HR data for exfiltration. Reconstructed end to end from endpoint and identity telemetry.
Microsoft Defender for Endpoint + KQL (Advanced Hunting)
A self-directed simulation of building a vulnerability management program from zero: policy drafting, stakeholder buy-in, prioritized remediation, and a validated scan-to-fix cycle end to end.
Tenable + Azure + PowerShell