SOC Analyst & Cyber Security Specialist
Building a career in cybersecurity — defending enterprise environments through threat detection, incident response, and continuous security monitoring. Outside the SOC: soccer, football, gaming, and music production.
The Lab
Real-world investigations and engineering projects. Details anonymised to protect client confidentiality.
New analysts and students entering cybersecurity lack engaging, hands-on environments to learn core concepts and terminology without expensive lab infrastructure.
Designed and built a short-form gamified CTF platform to teach fundamental cybersecurity functions and terminology through interactive challenge-based learning.
A fully functional platform hosted on GitHub, providing a free, accessible entry point for learners to build foundational security knowledge in a structured game format. Submitted as the final capstone project for a BSc (Hons) Cyber Security at The Open University — graduating with a 2:1.
Needed a 24/7 AI-accessible assistant capable of running automated security tasks and background jobs without exposing personal data or risking a compromised host environment.
Wiped a laptop to a clean state and hardened it as a dedicated home server with secured ports and a locked-down security posture. Deployed OpenClaw with WSL2, integrated Google Gemini Flash, and configured a Telegram bot for 24/7 mobile access via a VPS relay.
A fully operational AI companion running 24/7 — reachable via Telegram from anywhere, capable of autonomous background tasks, and hosted on isolated hardware with no personal data exposure.
InsightConnect Automation · Rapid7 + Cortex XDR Integration
Containing a potentially compromised endpoint required pivoting across multiple consoles, adding friction and time during an active incident where speed matters most.
Built a Teams-triggered host isolation workflow in Rapid7 InsightConnect. An analyst types contain-host <asset> in the designated channel. The workflow looks up the host in Cortex XDR, prompts the analyst with a human-in-the-loop confirmation gate, isolates on approval, then automatically pulls forensic artifacts — running processes, network connections, and the IDR timeline — and posts a snapshot card back to the thread. An audit log entry is written to InsightIDR before the flow exits. Declined requests exit cleanly with an “Operation Aborted” post.
Reduces time-to-containment from a multi-step manual process across two consoles to a single Teams message. Forensic context is captured automatically at isolation time, preserving evidence without analyst intervention.
Terminal
Short-form technical notes from the trenches. Updated periodically.
Microsoft Defender’s scanning engine runs with SYSTEM privilege, which makes it a useful proxy for an attacker who wants to read something they cannot touch directly. ShieldCrash abuses exactly that: a symlink planted under a system config path redirects MsMpEng.exe into opening one of the Windows credential hives — SAM, SECURITY or SYSTEM — so Defender harvests the credential material on the attacker’s behalf. I hunted it in Cortex XDR with an XQL query keying on FILE_OPEN and FILE_LINK_READ events where the actor process is MsMpEng.exe and the resolved path terminates at one of the three hives. An unfiltered baseline confirmed the query matched real telemetry; the full logic then returned zero hits across a 30-day lookback. With no out-of-the-box detection confirmed to cover the technique, the hunt was promoted to a standing BIOC rule.
Microsoft disclosed a new ClickFix variant that abuses nslookup to retrieve second-stage payloads over DNS rather than HTTP — making it harder to catch with traditional web-request detections. The full attack command runs through cmd.exe, performs a DNS lookup against a hardcoded external resolver, then pipes the output through findstr "^Name:" to extract and execute the payload embedded in the DNS response. I built a detection rule in Cortex XDR using XQL to surface this behaviour, keying on process events where the command line contains nslookup combined with findstr — a combination that has no legitimate use case in the environment and fires with high confidence and minimal false positive risk.
Initial entry confirming the terminal feed is rendering correctly. Further write-ups will follow as investigations and detection work is documented.
Credentials
Validated expertise across vendor and academic pathways.
The Open University
Graduated — 2:1 Honours
CompTIA — SY0-701
To verify, visit the link and enter the code: c993b2cbcd2440fcb12752909c8406c6
Palo Alto Networks
Certificate of Completion — September 2026
Training hours 12:25 · ID C596136
Palo Alto Networks
Certificate of Completion — September 2026
Training hours 04:25 · ID C596121
Active subscriber — ongoing hands-on lab practice across offensive and defensive tracks.
View Profile ↗Technical Arsenal
Core competencies across detection engineering, response operations, and identity security.
Authoring detection rules and hunting queries across enterprise SIEM and XDR platforms to surface anomalies and TTPs aligned to MITRE ATT&CK.
End-to-end IR from initial triage through containment, eradication, and post-incident review. Proficient in enterprise EDR and XDR platforms.
Securing identities at scale — managing Conditional Access, Privileged Identity Management, and investigating identity-based attack chains.
Building and maintaining dashboards, alert rules, and correlation logic to maintain situational awareness across multi-cloud environments.
Accelerating SOC workflows through SOAR playbooks, custom Python utilities, and PowerShell scripts for rapid triage and enrichment.
Monitoring and securing cloud workloads, reviewing IAM postures, and investigating cloud-native threats across Azure environments.
Contact
Open to incident response consultancy, detection engineering projects, and cybersecurity roles. Reach out via any channel below.
For sensitive communications, encrypt messages using the public key below. Verify the fingerprint independently before sending.