Three years in a 24/7 security operations centre — triage, incident investigation, escalation, and the runbook and detection work that comes after. CySA+ certified. Currently going deep on detection engineering and AI-assisted triage.
ensign infosecurity · ensoc-mys · night shifts · qradar / sentinel / splunk / logrhythm
Alert triage and incident investigation across SIEM and EDR, IOC and phishing analysis, escalation and ticket discipline. The unglamorous part that decides whether a SOC works.
Lab write-ups: the rule, the telemetry, the false-positive result. Method first, no vendor slides. Read the notes.
Agentic security tooling I build and run myself — autonomous research agents on sanctioned platforms, and a client-side multi-model console. See projects.
Everything published here is lab-derived. Employer and client incident data never appears on this site, in any form. Anonymised case write-ups exist for interviews and stay private. Verifiable tooling lives on GitHub.
IBM QRadarMicrosoft SentinelSplunk LogRhythmCrowdStrike FalconTrellix VectraTrend Micro ApexVirusTotal AbuseIPDBCisco TalosIBM X-Force MITRE ATT&CKSigmaPython