Engineering proactive, scalable security systems that drastically reduce adversary dwell time.
"The best threat hunting is done before the threat knows it's being hunted."
I believe in Proactive Defense and High-Fidelity Detection. My approach focuses on Adversary Emulation and Defense Optimization — rigorously testing security controls against realistic attack scenarios, minimizing false positives, and ensuring SOC teams focus on true signals, not noise.
| Area | Description |
|---|---|
| 🧪 Attack Simulation | Enhancing Event-Horizon with multi-vector attack telemetry for realistic detection validation |
| 📊 SIEM Engineering | Expanding production-ready detection coverage in Splunk SPL and Microsoft KQL |
| 📱 Splunk App Development | Building a custom SOC operations app targeting Splunkbase deployment |
| 🛠️ Security Tooling | Engineering automation tools (SCOUT, Hyper-SOC) to eliminate analyst toil |
| Domain | Technologies | Value |
|---|---|---|
| Detection Engineering | Splunk SPL, KQL, XQL | Production-grade, MITRE-aligned detection rules across SIEM & EDR |
| Splunk Dashboards & Reports | SPL, Splunk UI, Data Models | Design and deliver executive-ready dashboards, analyst reports, and real-time SOC monitoring views |
| Security Tooling | Python, Shell | Build tools that accelerate testing, training, and SOC workflows |
| Threat Intelligence | CVE tracking, IOC management, OSINT | Operationalize threat data into actionable defence |
| Threat Hunting | Behavioral analysis, custom queries | Surface stealthy threats that evade automated controls |
| SOC Operations & Incident Response | SIEM, EDR, Ticketing | Rapid alert triage, containment, and incident lifecycle management |
| Project | Stack | Description |
|---|---|---|
| 🌐 SCOUT | Python | Security & CVE Outbreak Universal Tracker — Real-time CVE monitoring, outbreak detection, and prioritization engine for enterprise SOC teams. Tracks zero-days and active exploitation across global threat feeds. |
| 🔭 Event-Horizon | Python / AI | Production-quality security log generator supporting 80+ platforms (Firewalls, Cloud, Endpoints, EDR). Generates realistic, timestamped attack telemetry for detection validation, SOC training, and dashboard testing. Features AI-powered attack simulation and "Golden Master" templates. |
| 🖥️ Hyper-SOC | Shell | One-command SOC Analyst workstation builder for Windows & Linux. Automates the full setup of a comprehensive SOC analyst environment — tools, integrations, and configurations — from a single script. |
| 🕵️ ProInfo Intelligence Suite | TypeScript / React | Professional-grade OSINT dashboard for streamlined IP reconnaissance and threat assessment. Features a "Cyber-Heatmap" for threat density, force-directed graph topology, and high-fidelity CSV/PDF reporting. |
| 🤖 Custom AI-Powered GPT | LLMs / Prompt Engineering | A specialized, knowledge-based GPT designed to democratize complex security expertise — streamlining analyst workflows, policy adherence checks, and detection logic creation. |
🔄 These libraries are living repositories — new rules, techniques, and coverage are added regularly as threats evolve.
| Project | Query Language | Description |
|---|---|---|
| ⚡ Splunk SPL Detection | SPL | 50+ production-ready detection rules, reports & dashboards mapped to MITRE ATT&CK. Includes a Techniques Library for SPL optimization and Universal Detection Archetypes. Deployable rule set and engineering cookbook. |
| 🛡️ Microsoft Defender KQL | KQL | Advanced hunting queries for M365 & Azure environments. Covers identity attacks (impossible travel, OAuth abuse), endpoint threats, and cloud telemetry — optimized for cloud-scale detection. |
| 🔎 Cortex XDR XQL Detection | XQL | Specialized XQL detection library optimized for Cortex XDR's BIOC framework. Focuses on behavioral detection to thwart fileless attacks and living-off-the-land (LotL) tactics. |
| Project | Stack | Description |
|---|---|---|
| 📊 Splunk SOC App (In Development) | Splunk / SPL / Python | A full-featured SOC Operations App targeting Splunkbase deployment. Consolidates threat detection, alert triage, CVE tracking, and analyst workflows into a single unified Splunk application. |
Detection Libraries: Splunk SPL · Microsoft KQL · Cortex XDR XQL
MITRE Coverage: Initial Access · Execution · Persistence · Privilege Escalation
Defense Evasion · Credential Access · Discovery · Lateral Movement
Collection · Exfiltration · Command & Control · Impact
Platforms Supported: Windows · Linux · macOS · Azure · M365 · Palo Alto · Fortinet · +more