You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This project required the built-in of high-confidence detections in Microsoft Sentinel using KQL, focusing on identity security and reducing false positives. This project targets MFA bypass and correlates signals like impossible travel and abnormal access patterns to detect real-world attacks.
Artefact conçu pour déplacer la surface d'action vers la représentation opérationnelle d'un système défensif. Pas d'exploitation, pas de persistance. L'espace cognitif comme terrain. Ce qui cesse d'être observé pendant la qualification est l'espace dans lequel il opère.
SOC-style phishing incident investigation analyzing a multi-vector job scam campaign. Performed email header analysis, URL inspection, and IOC extraction; mapped attack techniques to MITRE ATT&CK and documented findings with remediation and responsible disclosure.
Cybersecurity Engineering student passionate about technology, security, and continuous learning. Building practical projects, exploring emerging technologies, and developing skills to solve real-world challenges.
AI-assisted SOC triage pipeline - real AD attack alerts fed through Claude API for automated Tier 1 analysis. Includes analyst dashboard, AI vs manual comparison, and documented hallucination found during failure testing.
Investigated suspicious Microsoft 365 sign in activity using portal triage, containment actions like session revocation and stronger authentication, then validated remediation and practiced structured KQL hunting patterns with Azure Monitor Logs demo data.
Enterprise security homelab simulating Active Directory, SIEM operations, threat detection, and internal attack scenarios in a virtualised on-prem environment.
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.