Featured Project
SentinelOPS — SIEM / SOC Telemetry Platform
An end-to-end security operations project investigating the lifecycle of telemetry: from raw endpoint event generation to high-confidence detection engineering and rapid analyst response.
Key Engineering Objectives
- Noise Reduction: Filtering benign telemetry while retaining actionable signals for lateral movement.
- Detection As Code: Version-controlled Sigma and YARA rules mapped to MITRE ATT&CK techniques.
- Adversary Simulation: Verifying detection coverage against automated adversary emulation scripts.
Technical Architecture
- Log Ingestion: Windows Event Logs (Security, Sysmon), Linux auditd, Suricata NIDS alerts.
- Pipeline: Centralized log forwarding, structured schema normalization, and enrichment.
- Triage Workbench: Fast context lookup for IOCs, process tree timelines, and automated severity scoring.