SIEM & Detection

  • ELK Stack
  • Elasticsearch
  • Logstash
  • Kibana
  • SIEM
  • Detection Engineering

Languages

  • Python
  • Rust
  • C#
  • JavaScript

Tools & Other

  • Git
  • Docker
  • Google Sheets API

I build security tooling because I want to understand how attacks work — and how to catch them. My SIEM-ELK project is a full SOC lab built from scratch: log ingestion with Logstash, detection dashboards in Kibana, custom alert rules. No guided labs, just raw infrastructure and genuine exploration.

I'm interested in detection engineering — the craft of writing rules that actually catch real threats without drowning in false positives. My background in AI gives me an interesting angle: I think about how LLMs and anomaly detection can augment, not replace, a SOC analyst's workflow.

I also ran a human-centred security research study on emoji-based passwords, comparing memorability vs security strength across different password schemes. Research that actually has practical implications.

currently exploring

Detection engineering workflows, SOC automation, and the intersection of AI and security operations.

Projects