// about
Your Name
Detection Engineer · MDR
Placeholder bio — replace this with your own. I work in managed detection and response, building and tuning detections across Microsoft Defender XDR and Microsoft Sentinel. Day to day that means connector engineering, RBAC and onboarding design for multi-tenant environments, KQL hunting, and turning messy telemetry into alerts an analyst can act on.
I started this site to write down the things that don't fit in a ticket: why a detection fired, what a clean onboarding actually looks like, and the trade-offs behind the security decisions teams make every day. If any of it saves you an afternoon, it did its job.
What I focus on
- Detection engineering and alert tuning in Defender XDR and Sentinel.
- Codeless (CCF) connector design, DCR transforms, and KQL parsers.
- Identity and access hardening across Entra ID and Azure.
- Incident response playbooks and threat hunting.
Get in touch
Best place to reach me is via the links in the footer. I'm always happy to compare notes on detections or talk shop about running a SOC.