Cybersecurity · SOC Analysis · Detection Engineering
MS Cybersecurity graduate from University of Houston. I run adversary emulation labs, triage real endpoint alerts, and document findings with the rigor of a practicing analyst. Focused on threat detection, adversary emulation, and building security controls grounded in real attack data.
These labs are a mix of fully self-directed projects and coursework I extended well beyond the original assignment and all executed and documented with the same rigor. They follow a deliberate progression: from building detection foundations, to full adversary emulation and threat intelligence, to original research identifying systematic gaps in enterprise EDR coverage. Each lab informed the next.
Extended the AI triage engine into a full SOAR pipeline. Two alert sources feed the same flow: real Splunk AD attack alerts and honeytoken triggers from fake privileged artifacts seeded into Active Directory. Every alert is enriched via VirusTotal and AbuseIPDB before Claude triages it, then a decision engine routes it to auto-close or escalate. Documented two AI behavior findings: enrichment measurably shifts Claude's confidence and verdict; AI hedges on honeytoken alerts where the false positive rate is zero by design, leading to a rule-based bypass for that path.
Built a Python pipeline that feeds real attack-generated Splunk alerts to the Claude API for automated Tier 1 SOC triage. Generated 38 alerts via live Kerberoasting, AS-REP Roasting, and lateral movement attacks, normalized NDJSON exports into a structured JSON schema, and displayed AI vs manual analyst verdicts in a custom dashboard. Caught a High-confidence AI hallucination during failure testing - inverted encryption type mapping on a Kerberoasting alert and documented why AI confidence scores cannot replace analyst judgment.
Simulated a full AD attack chain: Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync, and BloodHound enumeration against a live domain environment, then investigated each technique from the analyst seat using Splunk SIEM with tuned Windows audit policies. Documented detection gaps including LDAP-based enumeration generating zero events across both SIEM and EDR layers.
Built an enterprise Active Directory lab (Windows Server 2022, domain-joined Windows 10, MITRE Caldera C2 on Kali Linux), executed three adversary profiles mapped to MITRE ATT&CK, and triaged live incidents in Microsoft Defender for Business. Identified systematic detection gaps for post-compromise staging techniques.
A few things currently being built. Details soon.
A structured, multi-year dataset and research paper examining how a financially motivated threat actor group has shifted toward exploiting trusted vendor relationships. Independent research, for educational purposes.
Built through hands-on lab work, not just coursework.
Open to Threat Analyst, Detection Engineer and SOC Analyst roles.
Actively seeking Threat Analyst, Detection Engineer and SOC Analyst roles. MS Cybersecurity graduate with hands-on experience in log analysis, attack simulation, detection engineering and SOC Analysis.