DETECTION ENGINEERING // MDR

Finding signal in the telemetry.

I build and tune detections across Microsoft Defender XDR and Sentinel, and write up what actually works when you run a SOC. This is where those notes live.

// what i work on

EDR

Detection Engineering

Writing, testing, and tuning analytics so real threats surface and the noise stays quiet.

SIEM

Microsoft Sentinel & CCF

Codeless connectors, DCR transforms, and KQL that turns raw logs into usable signal.

XDR

Defender XDR

Endpoint and identity coverage, RBAC models, and multi-tenant onboarding done right.

CLOUD

Azure & Entra Security

Hardening identity, access, and cloud posture across Entra ID and Azure workloads.

IR

Incident Response

Triage, hunting, and containment playbooks that hold up under a live incident.

COMM

Community & Writing

Sharing detections, teardowns, and lessons learned so the next analyst moves faster.

// latest writing

All posts →