// PROOF OF WORK

What I've built

This isn't a list of technologies on a CV. It's the evidence: every tool, lab and detection system here I built myself, organized by skill. Click any of them and check.

// don't say you know KQL — prove it

Detection Engineering

From a real log to the rule, and from the rule to its quality.

SOC · Microsoft Sentinel · KQL

KQL over real logs and an arsenal ready for Sentinel/Defender.

Incident investigation

Investigate a real incident end to end and issue a verdict.

Threat Intel & Vulnerabilities

What's exploited now, who it affects and what to patch first.

Phishing & email auth

Phishing verdict and a domain's path to DMARC p=reject.

MITRE ATT&CK

The arsenal mapped over the matrix, technique by technique.

Offensive & Active Directory

How an attacker thinks: privilege paths to Domain Admin.

Fundamentals, "how it works"

I explain the internals an analyst takes for granted.