- I learn to work across the defensive security lifecycle, like - simulating attacks and defending systems to understand how threats work and how they should be detected.
- Currently pursuing BCA, with a focus toward SOC operations, detection engineering, and threat hunting. My approach is real workflow exposure: triaging alerts, analyzing logs, and constructing context around security events.
- I'm currently focused towards mastery.
Develop mastery in detection engineering and threat hunting, while designing and building practical defensive security tooling for real-world SOC and endpoint security environments.
Focus areas:
- Log & Traffic Analysis
- Network-level visibility and traffic intelligence
- Detection engineering (behavioral logic)
- Automated response pipelines
- Investigation-ready telemetry and log structuring
- Adversary simulation for detection validation
| Area | Capability |
|---|---|
| Network Defense | Packet inspection, traffic profiling |
| Detection Engineering | Behavioral rules, MITRE ATT&CK alignment |
| SOC Operations | Alert triage, investigation workflows, response automation |
| OSINT | Passive recon, infrastructure context mapping |
| Security Engineering | CLI-first tools, modular architectures, reproducible workflows |
| Domain | Techniques | Tools |
|---|---|---|
| Detection Engineering | Signature + heuristic detection, ATT&CK mapping | Elastic Stack, Wazuh, MITRE ATT&CK, CAR, D3FEND |
| Network Analysis | Packet dissection, TCP/IP internals, anomaly detection | Wireshark, Nmap, TShark |
| OSINT | Passive intelligence gathering, infrastructure profiling | OSINT workflows |
| Development | CLI tooling, automation pipelines | Python, C#, Bash |
| Home Lab | Virtualized security labs and test environments | VMware, VirtualBox, WSL, Linux, Windows |
| Project | Domain | Stack | Status | Link |
|---|---|---|---|---|
| PacketHorn | Network Intrusion Detection & Response | C#, SharpPcap, CLI, INI-based config | Active Development | View |
| PacketWatch | Wireless Threat Monitoring | ESP32-S3, LoRa SX1278, FreeRTOS | Planned | N/A |
| Category | Stack |
|---|---|
| Languages | C#, Python, Bash |
| Network & Security | Wireshark, Nmap, Burp Suite |
| Detection & Analysis | ELK Stack, Custom Rule Engines |
| Labs | TryHackMe, LetsDefend, ATT&CK simulations |