Cybersecurity Skills & Expertise
Comprehensive matrix of security operations, threat detection tools, network forensics protocols, and scripting languages.
Threat HuntingCORE
Hypothesis-driven threat hunting targeting persistence, privilege escalation, and lateral movement.
Detection EngineeringCORE
Designing, testing, and tuning high-fidelity detection rules mapped to MITRE ATT&CK.
Incident ResponseCORE
End-to-end incident handling, root-cause analysis, containment, and eradication playbooks.
MITRE ATT&CK FrameworkCORE
Mapping adversary TTPs, gap analysis, and defense validation across enterprise matrix.
Malware Analysis
Static and dynamic analysis using sandbox artifacts, Ghidra, and process monitors.
Digital Forensics
Memory forensics (Volatility), registry triage, log analysis, and MFT parsing.
Threat Intelligence
Ingesting CTI feeds, IOC enrichment, MISP integration, and threat actor profiling.
IOC Analysis
Extracting, normalizing, and verifying hashes, domain indicators, and C2 IPs.
Wazuh SIEMCORE
Architecting open-source XDR/SIEM, agent deployment, XML rule tuning, and decoder writing.
CrowdStrike FalconCORE
EDR telemetry monitoring, custom IOA creation, real-time response (RTR), and host isolation.
Splunk Enterprise
SPL query development, dashboard creation, data parsing, and Enterprise Security alerts.
Microsoft Sentinel
KQL query engineering, workbook dashboards, Azure AD audit logs, and analytic rules.
TCP/IP & Suite
Deep packet inspection, protocol analysis, three-way handshake validation, and frame header triage.
DNS & HTTP/S
DNS tunneling detection, TLS certificate analysis, HTTP header inspection, and proxy logs.
Firewalls & VPNs
Next-Gen firewall rule management (Palo Alto / Fortinet), IPsec/SSL VPN monitoring.
Routing & Switching
VLAN segmentation, enterprise network topology, NAT traversal, and SPAN port mirror setup.
PowerShell
Windows event log analysis, script auditing, AMSI bypass detection, and AD administration.
Bash / Shell
Linux system administration, log processing with grep/awk/sed, and automated cron jobs.
SQL
Querying relational databases, analyzing Osquery endpoints, and log correlation.
JavaScript / Node
Building web tools, automating webhook integrations, and client-side security verification.
Wireshark
PCAP packet dissection, stream follow, display filter mastery, and rogue traffic identification.
Burp Suite
Web application traffic interception, repeater analysis, and API endpoint auditing.
Nessus
Vulnerability assessment scanning, credentialed audit reports, and patch prioritzation.
Nmap
Host discovery, port scanning scripts (NSE), service version detection, and firewall evasion.
Metasploit Framework
Emulating adversary payload delivery for blue team detection validation and lab testing.
VirusTotal
Multi-engine malware scanning, file hash analysis, URL reputation checking, and threat intelligence enrichment.
AbuseIPDB
Reporting and checking IP addresses for malicious activity, threat intelligence sharing, and reputation monitoring.
Shodan
Internet-connected device discovery, vulnerability assessment, banner grabbing, and network reconnaissance.
Kali Linux
Penetration testing and security auditing Linux distribution with comprehensive security tools collection.