U.S. Army veteran · security operations

Disciplined investigation. Defensible evidence.

SOC Analyst Incident Response Detection Engineering

I build and document hands-on security operations work across Microsoft Sentinel, Defender, Wazuh, Windows telemetry, and network evidence—combining technical analysis with 12 years of Army leadership.

Case files · 01–03

Selected Security Work

Three evidence-backed examples of cloud detection, endpoint triage, and network analysis.

Microsoft Sentinel lab interface

Case 01 · SIEM / SOAR

Microsoft Sentinel + Defender

Problem
Prove an end-to-end cloud security operations path from telemetry to response.
Built
Log Analytics ingestion, KQL analytics, Sentinel incidents, and a Logic Apps enrichment playbook.
Validation
Made a controlled NSG rule change and checked the event, rule, incident, and playbook path.
Outcome
The case file documents Azure Activity ingestion, KQL analytics, incident triage, and successful Logic App run history.
Windows Log Triage report preview

Case 02 · Endpoint DFIR

Windows Log Triage

Problem
Reduce the manual effort required to review EVTX and Sysmon evidence.
Built
A Python triage tool for IOC extraction and Sigma-like suspicious behavior hits.
Validation
A clean-wheel run processed five sanitized records with zero skipped records and zero parse errors.
Outcome
The package produces escaped HTML plus JSON/CSV output and records parser completeness for analyst review.
PCAP Quick Profiler report preview

Case 03 · Network DFIR

PCAP Quick Profiler

Problem
Turn raw packet captures into a fast first-pass analyst view.
Built
An installable profiler with complete-capture statistics, protected reports, and public-unicast-filtered VirusTotal enrichment.
Validation
Checked totals against TShark and added a deterministic packet fixture to Repository CI.
Outcome
The latest review also blocks private, reserved, multicast, ULA, and malformed values before VirusTotal requests.

Secure development

Security Tools Engineering

How three analyst utilities were hardened through threat modeling, regression tests, packaging assurance, evidence governance, and CI/CD.

Network evidence

PCAP Quick Profiler

TShark-validated totals, protected reports, and globally routable unicast filtering before optional VirusTotal requests.

Endpoint evidence

Windows Log Triage

Safe EVTX paths, parser-completeness metadata, validated indicators, and escaped HTML/JSON/CSV output.

Hostile source

Eval Unpacker

Bounded reconstruction without JavaScript execution, 35 focused tests, and 91% core coverage.

Response method

SOC Playbooks

How I scope and document common alert types.

Suspicious PowerShell

Correlate 4104, 4688, and Sysmon telemetry; review encoded commands, process ancestry, payloads, persistence, and network activity.

SharePoint Privilege Escalation

Review public-facing application evidence, authentication changes, uploaded files, privilege changes, containment, and patch status.

Malicious Office Document

Connect message source and attachment evidence to Office child processes, scripting engines, dropped files, network traffic, and user impact.

Leadership

Military experience applied to cybersecurity

12 years in the U.S. Army, including two deployments and Staff Sergeant leadership responsibilities.

Prioritize under pressure

Make time-sensitive decisions with incomplete information and prioritize incidents by risk and mission impact.

Coordinate response

Communicate across technical and nontechnical teams while maintaining accountability and procedural discipline.

Build repeatability

Train personnel, document procedures, and coordinate work across multiple stakeholders.

Field notes

Latest Technical Writing

Recent incident investigations, lessons learned, and security research.

Contact

Ready to support a security team

Open to SOC, incident response, and detection engineering roles in Killeen, Texas, including remote and on-site opportunities.