my projects.

Personal Project

GrantScope — Entra ID OAuth & Service Principal Risk Investigator

Built a cloud identity investigation tool to analyze OAuth applications, service principals, permission grants, app credentials, privileged app-role assignments, owners, sign-in activity, and directory audit events.

  • Designed correlation logic for risky tenant-wide grants, credential changes, missing owners, privileged service principals, suspicious consent, and unusual app usage.
  • Generated analyst-ready case packets with evidence timelines, risk rationale, remediation steps, and handoff notes.
  • Implemented evidence-bundle imports and structured findings into cases, suppressions, and reviewable observations.
Cloud Security
Entra ID
FastAPI
Identity Security
OAuth
PostgreSQL
Service Principals
Personal Project

SignalProof — Telemetry Contract & Detection Validation Platform

Built a contract-driven platform to validate endpoint telemetry, required event fields, detection quality, and detection latency against YAML-defined security testing contracts.

  • Designed an ATT&CK-mapped validation engine for telemetry checks, detection review, and latency tracking.
  • Integrated Wazuh/OpenSearch-style validation to diagnose collection, parsing, ingestion, and detection failures.
  • Developed FastAPI APIs, PostgreSQL persistence, evidence reports, regression comparison, and a Streamlit dashboard.
ATT&CK
Detection Validation
FastAPI
OpenSearch
PostgreSQL
Streamlit
Wazuh
YAML
Practical SOC Lab Work

Blue Team / SOC Analyst Portfolio Repository

A public repository documenting practical SOC lab work across endpoint monitoring, incident investigation, threat hunting, detection tuning, and basic automation in controlled environments.

  • Organized lab-based incident reports, hunts, detections, scripts, and monitoring notes.
  • Documented investigation logic, evidence sources, detection reasoning, and analyst-oriented conclusions.
  • Used the repository as a public evidence base for junior SOC and detection-engineering readiness.
Detection Engineering
Incident Response
SOC
Sigma
Sysmon
Threat Hunting
Wazuh
Private Internship Project — Publication Planned

CTI-Driven Detection Engineering Platform

A CTI-to-detection engineering platform that ingests MISP indicators, normalizes IOCs, maps activity to MITRE ATT&CK, assesses telemetry readiness, tracks detection gaps, and produces SOC-ready detection use cases.

Detection Engineering
KQL
MISP
MITRE ATT&CK
SPL
Sigma