Security Researcher | Detection Engineer | Threat Hunter | Adversary Emulator
Breaking things to build better defenses.
Chasing APTs, crafting rules, emulating red-team TTPs, and turning bugs into detections.
- π Threat Hunting β Proactive, hypothesis-driven hunts across endpoints, cloud & networks
- π οΈ Detection Engineering β Building scalable, low-FP detections (Sigma, YARA, Elastic, Splunk, custom queries, etc.)
- βοΈ Threat Emulation β Adversary emulation, purple teaming, ATT&CK-based red-team ops
- π§ͺ Security Research β Reverse engineering malware, vuln discovery, exploit dev & analysis
- Languages: Python β’ Go β’ PowerShell
- Detection: Sigma β’ YARA β’ Zeek β’ Suricata β’ Elastic β’ Splunk β’ Microsoft Sentinel
- Hunting/EDR: Velociraptor β’ GRR β’ Osquery β’ Falcon β’ Defender XDR β’ CrowdStrike
- Emulation: Caldera β’ Atomic Red Team β’ Infection Monkey β’ Metta
- Reverse: Ghidra β’ IDA Pro β’ radare2 β’ x64dbg
- Living-off-the-land binaries & techniques (LOLBAS)
- Cloud threat emulation (Azure AD / AWS IAM abuse paths)
- Next-gen ransomware TTPs & detection gaps
- AI-assisted threat hunting & anomaly baselining
