I build detections, tune them until they're quiet, and write up what they catch. Aiming at SOC and blue team roles. Best way to reach me: LinkedIn.
Featured: beacon-hunter
Finds malware "phoning home" in network logs, explains every finding in plain English, and writes a one-file report you can attach to a ticket. Reads Zeek, Suricata, Sysmon, CSV exports and raw packet captures.
The write-up covers what it misses, and a mistake I caught and corrected along the way.
Built for a network security course at Seneca. Attacks come only from outside, through the DMZ, and every one has to show up as a specific alert someone can act on.
The lab itself stays private (it's coursework and holds credentials), but I'm glad to demo it or walk through any rule.