Protecting the Digital World
SOC · Detection Engineering · Microsoft Sentinel · KQL · eCPPT
I don't claim it — I build it. Security tools, detection systems and interactive labs that show how attacks are detected, investigated and contained.
👔 Recruiter? 60-second view →Five families, 66 tools. The ones handling your data —emails, logs, passwords— run entirely in your browser: nothing is uploaded anywhere.
Phishing triage, Sigma/KQL rules, log analysis and email auth.
Browse → 18 toolsCVSS calculator (v3.1 & v4.0), prioritization and vuln analysis.
Browse → 10 toolsReverse shells, payloads and offensive pentesting utilities.
Browse → 7 toolsDNS, WHOIS, public footprint and domain recon.
Browse → 14 toolsBase64, hashes, CTF multi-decoder, timestamps and URL.
Browse →47 of 226 have no DMARC policy preventing the domain of their corporate website from being used to send forged email. In the IBEX 35, 11 of 35. Monthly public DNS data, an open methodology and a per-company lookup.
Three interactive labs: defense, offense and architecture.
Interactive SIEM: write KQL-style queries over real logs, detect the attack and isolate the actor. My Azure Sentinel specialty, playable in the browser.
Active Directory attack-path simulator: enumerate, chain privileges and reach Domain Admin. See how an attacker thinks inside a domain.
Generates a tailored security architecture (size, ecosystem, compliance) with a diagram, controls and cost estimate. From theory to real design.
Technical notes from an analyst: detection, hardening and response.
Two products born from the same idea as this site: measure instead of assume.
Starter kit for AI applications, with the prompt-injection guardrail already implemented and measured against four attacks. The module and the attack suite, published in full before anyone is asked for money.
Describe a manual process in your company and get what it costs per year, how much can be automated, at what risk and where to start. Every figure with its confidence level; no data, no figure.