What I've built
This isn't a list of technologies on a CV. It's the evidence: every tool, lab and detection system here I built myself, organized by skill. Click any of them and check.
// don't say you know KQL — prove it
Detection Engineering
From a real log to the rule, and from the rule to its quality.
SOC · Microsoft Sentinel · KQL
KQL over real logs and an arsenal ready for Sentinel/Defender.
Incident investigation
Investigate a real incident end to end and issue a verdict.
Threat Intel & Vulnerabilities
What's exploited now, who it affects and what to patch first.
Phishing & email auth
Phishing verdict and a domain's path to DMARC p=reject.
MITRE ATT&CK
The arsenal mapped over the matrix, technique by technique.
Fundamentals, "how it works"
I explain the internals an analyst takes for granted.