Brute-Force Authentication
11,970 failed logons against a single account on one host within minutes.
Threshold: 10 failures / 5 min. Fires as a scheduled analytics rule with entities mapped for one-click pivot to host & account.
RSOC Operator · Detection Engineer
I run the Regional Security Operations Centre for a NASDAQ-listed semiconductor company — triaging alerts, engineering detections, and turning signal into proof. This site is the proof.
RSOC Operator at Synopsys covering the EMEA region — triaging 800+ alerts a shift across SIEM, CCTV/VMS and access control, and building the detections, dashboards and pipelines that explain them. Published time-series researcher. CompTIA Security+ (in progress).
Real analytics rules and tooling — mapped to MITRE ATT&CK, with the honest story of what fired, what didn't, and why.
11,970 failed logons against a single account on one host within minutes.
Threshold: 10 failures / 5 min. Fires as a scheduled analytics rule with entities mapped for one-click pivot to host & account.
Same account signs in from Dublin then Lagos 35 minutes later — implied 9,051 km/h.
Geo-velocity rule with entity mapping; raised as an incident with account + IP entities for fast triage.
Time-based rule returned zero rows — collector was stamping ingest time, not event time.
Lesson captured: a rule on collapsed timestamps looks healthy but fires on nothing. Now gated on true event time.
CLI that scores auth, sender identity, payload and language on a suspicious .eml and shows its reasoning.
Phish scores 100/100, a legitimate overdue-invoice chase scores 10/100 — a tool that flags everything trains analysts to ignore it.
Incident root cause was a parked p=none DMARC policy letting failed-SPF mail through.
Proposed control-health monitor that alerts when a domain's DMARC drops below p=quarantine.
Three KQL analytics rules mapped to MITRE ATT&CK with false-positive tuning notes and investigation runbooks.
End-to-end build of a click-to-C2 scenario: timeline, execution chain, IOCs, ATT&CK mapping and containment actions.
Tooling to surface C2 beaconing behaviour from network logs using jitter and periodicity analysis.
A pipeline that converts hunting hypotheses into Sigma rules and ships them to a SIEM-backed lab.
SARIMA model for atmospheric CO₂ concentration forecasting. MAE < 1 ppm. Published on Zenodo with DOI.
Anomaly detection on VPN connection telemetry to flag impossible travel and credential abuse patterns.
A phishing incident write-up where the root cause wasn't the user — it was a parked DMARC policy.
The third rule returned nothing — and that's the one worth sitting with.
Detection isn't about walls; it's about understanding baselines.
Targeting SOC Analyst, Security Operations, GSOC and detection engineering roles in Ireland and remote EU. Stamp 1G — full right to work, no sponsorship required.
[email protected]