Detection Engineering
Writing, testing, and tuning analytics so real threats surface and the noise stays quiet.
DETECTION ENGINEERING // MDR
I build and tune detections across Microsoft Defender XDR and Sentinel, and write up what actually works when you run a SOC. This is where those notes live.
// what i work on
Writing, testing, and tuning analytics so real threats surface and the noise stays quiet.
Codeless connectors, DCR transforms, and KQL that turns raw logs into usable signal.
Endpoint and identity coverage, RBAC models, and multi-tenant onboarding done right.
Hardening identity, access, and cloud posture across Entra ID and Azure workloads.
Triage, hunting, and containment playbooks that hold up under a live incident.
Sharing detections, teardowns, and lessons learned so the next analyst moves faster.
// latest writing
All posts →What actually matters when you move a connector to the Codeless Connector Framework.
The one early decision that shapes every permission you assign afterwards.
A short intro to what this blog is for and who it is for.