Purple Teamer · DFIR. Adversary Emulation · Detection Engineering
I work both sides of the fight: researching how attackers operate, then turning that tradecraft into open-source hunting queries and detections defenders can use right away.
- CB-Threat-Hunting · Threat hunting queries for Carbon Black
- DefenderATPQueries · Advanced hunting queries for Microsoft Defender for Endpoint
- Project-Lost · Living Off Security Tools
- awesome-email-security · Curated enterprise email security resources
- Sysmon · Sysmon configs for Windows and Linux
- WebShellsThreatGroups · Webshells mapped to threat groups for emulation and detection testing
Tools: Defender for Endpoint (KQL) · Carbon Black · Sysmon · YARA · Sigma · Velociraptor · C++. C#. ASP.net. Python




