TECHNICAL ARSENAL

Skills & Tools

A comprehensive breakdown of my enterprise production stack, auxiliary engineering tools, and training background.

Core Platforms & Professional Experience

Tool: Datadog

Platform Expertise: Real-time signal triage, log ingestion pipelines, billing/cost management, workflow automation.

Tool: CrowdStrike

Platform Expertise: Endpoint detections, AIDR, DLP, SaaS Security, host management, advanced event search, and CrowdStrike Intelligence & Sandbox.

Tool: Material Security

Platform Expertise: Phishing investigations, file sharing and permissions management, account takeover (ATO) resilience.

Tool: Notion

Platform Expertise: Notion power user; custom signal triage queue, detection rule registry, SOC operation runbooks, knowledge-base.

Incident Response & Operations

Incident Liaison / Tech Lead: Acted as SME managing the full lifecycle of security incidents through to post-mortem (via incident.io).

OSINT & Threat Intel

Analysis Tools: VirusTotal, AbuseIPDB, app.any.run, URL2PNG, CyberChef, Scamdoc, and GreyNoise for live threat enrichment and artifact analysis.

Frameworks & Compliance

  • MITRE ATT&CK Framework: Mapped custom detection rules and playbooks to adversary tactics.
  • ISO 27001 Framework: Applied operational security standards (e.g., threat intelligence annex).
  • NIST SP 800 Framework: Scoped all runbooks and IR procedures.

Auxiliary Technical Stack & Engineering

Scripting & Automation

Python, API integrations.

Infrastructure & CI/CD

Unix/Linux log monitoring, GitLab pipelines, change management workflows.

Training, Labs & Additional Tooling

  • SIEM: Splunk
  • Network & Forensics: Wireshark, Nmap, Autopsy, FTK Imager, ExifTool
  • Honeypots: Cowrie
  • Active Learner: TryHackMe, LetsDefend.io, BlueTeamLabs.online