I work in security operations and spend most of my time investigating alerts, reviewing logs, tuning detections, and understanding how incidents unfold across endpoints, identities, and cloud environments.
- Threat detection and SIEM rule logic
- Endpoint telemetry and EDR investigations
- Windows event logs, Sysmon, and process behavior
- KQL, AQL, PowerShell, and Python for security analysis
- Cloud and identity-focused security monitoring
- Digital forensics and incident response fundamentals
SIEM & Security Platforms
EDR & Endpoint Security
Languages & Querying
Analysis & Monitoring
- SOC and blue team labs
- SIEM detection logic
- Threat simulation writeups
- KQL and AQL queries
- Incident investigation notes
- Windows and cloud security learning projects
- Reading 📖
- Sketching ✏️
- Baking 🍪