Threat detection & response
Monitoring, alert triage and mitigation across endpoint, network, email and identity.
Hi, I'm
Cybersecurity Engineer Penetration Tester CEH
I specialise in threat detection & response
I detect, investigate and contain threats, harden the environments attackers target, and test defences the way an attacker would. Five-plus years across security operations, engineering and offensive security.
I started in security operations, triaging alerts and learning what attackers actually do. Today my core work is threat detection and incident response: spotting what's wrong, investigating it, containing it and making sure it can't happen the same way twice.
Around that core I build the systems that make detection work, with 100+ SIEM and SOAR use cases, EDR, XDR and MDR rollouts across several platforms, and hardened endpoints, email and identity. I also analyse malware and run investigations end to end.
On the offensive side I'm a penetration tester and bug bounty hunter. I run red team simulations and tool POCs, which means I test defences the way an attacker would, then help fix what I find. I also train schools, colleges and institutions on staying safe from cyber crime.
Eight areas, in order of how much of my time they take.
Monitoring, alert triage and mitigation across endpoint, network, email and identity.
Scoping, containment, root cause, malware analysis, forensics and recovery support.
Authorised web and infrastructure testing, attack simulations and tool POCs.
100+ detection and automation use cases, log onboarding, dashboards and playbooks.
EDR, XDR and MDR across platforms, secure baselines, patching and exposure reduction.
Microsoft 365, Entra ID, BEC controls, SPF, DKIM, DMARC and sign-in investigations.
Assessment, validation, prioritisation, remediation tracking and retesting.
Reputation analysis, reconnaissance, dark web monitoring and fraud attribution.
How the work fits together. Every diagram is live: hover or tap a component to see what it does. Client details are deliberately left out.
Detection and investigation run across the top; containment and recovery come back along the bottom.
Core workDay to day
Across multiple EDR, XDR and MDR platforms
My core duty: watching security telemetry, triaging alerts, investigating what is real, and containing threats before they spread. I work across several EDR, XDR and MDR platforms, so the method matters more than any single tool.
Detection is built across the top; automation and response come back along the bottom.
Detection engineeringBuilt at scale
100+ detection and automation use cases
Building the detection layer itself: onboarding log sources, writing correlation searches and use cases, and automating repetitive investigation with SOAR playbooks. One example is a playbook that catches suspicious VPN logins, deduplicates the source IPs and enriches them with threat intelligence before deciding whether to alert.
The attack runs across the top; detection checks and the report come back along the bottom.
Offensive securityAuthorised testing
Web, infrastructure and autonomous testing
Authorised penetration testing of web applications and infrastructure, plus red team simulations that check whether defences catch a real attacker. Because I also work on the defensive side, every finding comes with practical remediation and a detection to match.
Rollout runs across the top; ongoing protection loops back along the bottom.
Endpoint securityMulti-platform
Rollouts, migrations and secure baselines
Securing endpoints across platforms: deploying and migrating EDR, XDR and MDR solutions, designing policies and exclusions, and hardening servers and workstations so attackers have less to work with.
Analysing suspicious files and behaviour, extracting indicators of compromise, and endpoint forensics to reconstruct what happened.
Mail-flow protection, BEC controls, quarantine and message trace, plus sign-in, MFA and mailbox-rule investigations.
Internal and external assessment, validation, risk-based prioritisation, remediation tracking and retesting.
Zscaler deployment and policy for secure internet and private access, with logs streamed into the SIEM.
Phishing simulation campaigns, targeted training for users who fail, and reporting on results.
Watching for leaked credentials and exposed data, and acting on them before they are used.
Hands-on evaluations before rollout: does it detect, does it scale, does it fit the environment?
Open-source intelligence for attribution, reconnaissance and fraud investigations.
Finding and responsibly reporting vulnerabilities in public bug bounty programs.
Real investigations, rewritten so nothing identifies a client, a person or a system. Open a file to see how it was handled.
Outcome Containment and recovery supported, with clear recommendations to close the remote-access gap.
AI coding assistants and CLI tools spawn PowerShell and Bash, write scripts and execute them: behaviour that closely resembles an attacker's. I evaluated each detection on process lineage and behaviour, separated legitimate developer activity from genuinely suspicious patterns, and scoped exclusions narrowly rather than switching protection off.
Takeaway Modern tooling needs detections judged on evidence, not silenced to stop the noise.
Outcome Attribution evidence submitted to law enforcement agencies.
Outcome Intelligence handed to law enforcement for action.
For companies, startups, institutes and teams that need hands-on security help. Available for freelance projects, training engagements and full-time roles.
Web applications, infrastructure and external attack surface, with a clear report and a retest.
SIEM, EDR, XDR and SOAR deployment, use cases and tuning that cut the noise.
Triage, containment, investigation and recovery guidance when something goes wrong.
Endpoints, servers, email and Microsoft 365 configured to resist real attacks.
Sessions for schools, colleges, institutions and teams on today's threats.
Independent hands-on evaluation before you commit to a security product.
I run cyber crime awareness sessions for schools, colleges and institutions: how today's scams and attacks actually work, and the habits that stop them. Tap a topic to see what audiences take away.
Been targeted? In India, report cyber fraud straight away on helpline 1930 or at cybercrime.gov.in. The faster it's reported, the better the chance of stopping the money.
Invite me to speakGrouped by capability. Platforms I have implemented, operated or tested with.
From security operations to security engineering and offensive security.
Promoted from Cybersecurity Engineer
Threat detection and incident response across multiple EDR, XDR and MDR platforms: alert triage, investigation, containment and mitigation. Endpoint hardening, email and identity security, vulnerability management, penetration testing, phishing awareness and dark web monitoring.
SIEM and SOAR engineering with 100+ use cases, log onboarding, dashboards, Zscaler implementation and autonomous penetration testing.
Security monitoring, alert triage, investigation, escalation and reporting.
Cybercrime investigation and security research internships, and bug bounty hunting.
Followed by a Master's program in cybersecurity.
What I keep practising and building outside client work.
Freelance projects, training sessions, speaking or full-time roles: tell me what you need.