Presentation
My experience includes campaign-based threat hunting across the attack lifecycle using Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Google Threat Intelligence (GTI), KQL, Sysmon, and MITRE ATT&CK.
Services I can provide:
Threat hunting based on IOCs, TTPs, intelligence, behaviors, and attack hypotheses
KQL query development and optimization for Microsoft Sentinel and Defender
Threat intelligence research, IOC enrichment, and campaign profiling
MITRE ATT&CK mapping and detection-gap analysis
Detection logic and security use-case development
Windows/Sysmon telemetry analysis and investigation
Suspicious process, network, authentication, persistence, and execution activity analysis
Ransomware and targeted-intrusion hunting
Hunt findings, technical reports, and actionable recommendations
I focus on turning raw security telemetry and threat intelligence into clear hypotheses, practical detections, and actionable findings that security teams can use to improve their defensive coverage.
I can also develop structured threat-hunting case studies and detection content


