Senior Threat Detection & Research - There is no anonymity on the attack surface, only delays!
I build and break detection pipelines for a living. My work sits at the intersection of Detection Engineering, Threat Hunting, DFIR, and SIEM/XDR architecture - writing the rules that catch the things generic configs miss, then trying to defeat them myself before someone else does. Wazuh Ambassador, contributing production-tested rulesets, adversarial simulation reports, and native Windows telemetry research to the community. I also run a personal honeypot/SOC lab on Splunk - building dashboards, SPL queries, and alerting from live attack traffic (geo-mapped attacker origins, service/port interaction analysis, user-agent fingerprinting) to keep detection instincts sharp outside of production work. When things go wrong despite it all, Incident Response is where I close the loop.
$ cat /etc/focus/areas
Blue Team Operations · Threat Intelligence · Threat Hunting · Adversary Simulation · Honeypot Research · DFIR · Incident Response · External Attack Surface Management (EASM) · SOC Automation · Detection Engineering · SIEM/XDR (Wazuh · Splunk)
Tech Stack:
GitHub Stats:


