// about
About this blog
Notes from a detection engineer on rules, tooling, and process.
What this is
A running log of detection logic, SOC process notes, and threat hunting write-ups. Mostly Sigma rules, EDR telemetry, and the occasional post-mortem on a detection that didn't work as intended.
Focus areas
Endpoint detection engineering, alert tuning and precision metrics, living-off-the-land technique coverage, and building detection content that survives contact with a real environment.
Background
Edit this section with your own bio — years in the field, tools you work with day to day, certifications, or whatever you want visitors to know about you.