Skills & Tools
A comprehensive breakdown of my enterprise production stack, auxiliary engineering tools, and training background.
Core Platforms & Professional Experience
Tool: Datadog
Platform Expertise: Real-time signal triage, log ingestion pipelines, billing/cost management, workflow automation.
Tool: CrowdStrike
Platform Expertise: Endpoint detections, AIDR, DLP, SaaS Security, host management, advanced event search, and CrowdStrike Intelligence & Sandbox.
Tool: Material Security
Platform Expertise: Phishing investigations, file sharing and permissions management, account takeover (ATO) resilience.
Tool: Notion
Platform Expertise: Notion power user; custom signal triage queue, detection rule registry, SOC operation runbooks, knowledge-base.
Incident Response & Operations
Incident Liaison / Tech Lead: Acted as SME managing the full lifecycle of security incidents through to post-mortem (via incident.io).
OSINT & Threat Intel
Analysis Tools: VirusTotal, AbuseIPDB, app.any.run, URL2PNG, CyberChef, Scamdoc, and GreyNoise for live threat enrichment and artifact analysis.
Frameworks & Compliance
- MITRE ATT&CK Framework: Mapped custom detection rules and playbooks to adversary tactics.
- ISO 27001 Framework: Applied operational security standards (e.g., threat intelligence annex).
- NIST SP 800 Framework: Scoped all runbooks and IR procedures.
Auxiliary Technical Stack & Engineering
Scripting & Automation
Python, API integrations.
Infrastructure & CI/CD
Unix/Linux log monitoring, GitLab pipelines, change management workflows.
Training, Labs & Additional Tooling
- SIEM: Splunk
- Network & Forensics: Wireshark, Nmap, Autopsy, FTK Imager, ExifTool
- Honeypots: Cowrie
- Active Learner: TryHackMe, LetsDefend.io, BlueTeamLabs.online