Detection engineering
Suspicious Parent–Child Process
A synthetic endpoint chain designed to build and validate behavioral detection logic in Microsoft security tooling.
Labs / case studies / experiments
A growing folder of synthetic incidents, detection logic, network-defense work, investigations, and the documentation that makes it reproducible.

Detection engineering
A synthetic endpoint chain designed to build and validate behavioral detection logic in Microsoft security tooling.
Network detection
Firewall and endpoint telemetry combined to identify suspicious movement across security boundaries.
Incident response
AI-assisted faux datasets for practicing investigation, scoping, detection development, and technical reporting in public.
STATUS: Detailed case studies and repository links are being assembled. The lab is operational; the filing system is a work in progress.