Blue-team pathway
experience & credentials
- FO
Cybersecurity / CTI Intern
Forvis Mazars GroupTunisiaMISPATT&CKSigmaKQLSPL- Developing a CTI-to-detection engineering platform that ingests MISP indicators, normalizes IOCs, maps activity to MITRE ATT&CK, and produces SOC-ready detection use cases.
- Built analyst workflows for IOC provenance, telemetry readiness, detection gap tracking, and report export.
- Generated Sigma/KQL/SPL-style detection templates for validation in SIEM workflows.
- Documented detection logic, evidence requirements, and analyst handoff notes.
- HA
Practical SOC Training
Hack The Box AcademyRemoteSplunkElasticSysmonSigmaYARA- Investigated simulated SOC cases in Splunk and Elastic by correlating Windows Event Logs, Sysmon activity, network indicators, and command-line artifacts.
- Reconstructed attack timelines involving suspicious PowerShell execution, C2 traffic, privilege escalation, and Active Directory-related behavior.
- Performed alert triage, IOC extraction, root-cause analysis, MITRE ATT&CK mapping, and incident reporting.
- Developed Sigma/YARA detection logic and translated findings into SIEM-oriented queries and analyst handoff notes.
- Reviewed IDS/IPS and network evidence from Suricata, Snort, Zeek, and PCAPs to validate suspicious traffic patterns.
featured security work
view moreGrantScope — Entra ID OAuth & Service Principal Risk Investigator
Built a cloud identity investigation tool to analyze OAuth applications, service principals, permission grants, app credentials, privileged app-role assignments, owners, sign-in activity, and directory audit events.
- Designed correlation logic for risky tenant-wide grants, credential changes, missing owners, privileged service principals, suspicious consent, and unusual app usage.
- Generated analyst-ready case packets with evidence timelines, risk rationale, remediation steps, and handoff notes.
- Implemented evidence-bundle imports and structured findings into cases, suppressions, and reviewable observations.
SignalProof — Telemetry Contract & Detection Validation Platform
Built a contract-driven platform to validate endpoint telemetry, required event fields, detection quality, and detection latency against YAML-defined security testing contracts.
- Designed an ATT&CK-mapped validation engine for telemetry checks, detection review, and latency tracking.
- Integrated Wazuh/OpenSearch-style validation to diagnose collection, parsing, ingestion, and detection failures.
- Developed FastAPI APIs, PostgreSQL persistence, evidence reports, regression comparison, and a Streamlit dashboard.
Independent Security Project
Cyblu
Cyblu is a small blue-team initiative focused on cyber visibility, detection gaps, and first defensive priorities for small organizations.
Security Notes
view moreFrom IOC to Detection Use Case: How CTI Becomes SOC Work
Currently BuildingA sanitized concept article on transforming threat intelligence into SOC-ready work through normalization, ATT&CK mapping, telemetry checks, detection templates, and analyst handoffs.
Read security noteCTIMISPMITRE ATT&CK+2July 22, 20262 min readOAuth and Service Principal Risk in Entra ID: What SOC Analysts Should Watch
Why OAuth applications, service principals, app credentials, owners, consent activity, and privileged app roles matter in cloud-security investigations.
Read security noteEntra IDOAuthService Principals+2July 21, 20262 min read