the blue team
Cyber Security
SOC operations, detection engineering, and security infrastructure.
Download CV ↓SIEM & Detection
- ELK Stack
- Elasticsearch
- Logstash
- Kibana
- SIEM
- Detection Engineering
Languages
- Python
- Rust
- C#
- JavaScript
Tools & Other
- Git
- Docker
- Google Sheets API
I build security tooling because I want to understand how attacks work — and how to catch them. My SIEM-ELK project is a full SOC lab built from scratch: log ingestion with Logstash, detection dashboards in Kibana, custom alert rules. No guided labs, just raw infrastructure and genuine exploration.
I'm interested in detection engineering — the craft of writing rules that actually catch real threats without drowning in false positives. My background in AI gives me an interesting angle: I think about how LLMs and anomaly detection can augment, not replace, a SOC analyst's workflow.
I also ran a human-centred security research study on emoji-based passwords, comparing memorability vs security strength across different password schemes. Research that actually has practical implications.
currently exploring
Detection engineering workflows, SOC automation, and the intersection of AI and security operations.
relevant work