Detection Engineering
PublishedSOC Automation with Splunk
Brute-force detection workflow using Windows authentication events, SPL alert logic, triage decisions, and repeatable analyst response notes.
Cyber Range Interface
A focused command view of security projects that move from attack simulation to detection logic, triage decisions, response notes, and measurable outcomes.
Featured Labs
Filter the lab board by discipline and open the work that has the strongest evidence trail.
Detection Engineering
PublishedBrute-force detection workflow using Windows authentication events, SPL alert logic, triage decisions, and repeatable analyst response notes.
Incident Response
StagedPhishing-to-malware scenario with host investigation, process review, log evidence, containment notes, and executive-ready incident documentation.
Identity Security
StagedOperational access-control scenarios covering MFA, least privilege, recovery controls, account lifecycle decisions, and escalation-resistant support workflows.
Analyst Briefing
Case Standard
Each project is framed around a practical security question: what happened, what evidence proves it, how should an analyst respond, and how can the workflow become repeatable?
Build a controlled scenario with enough realism to produce meaningful telemetry.
Write detection logic, validate the signal, and document false-positive boundaries.
Translate raw events into analyst-ready findings with clear severity and scope.
Package the response workflow so the same pattern can be repeated and improved.