project_explorer.exe

Labs / case studies / experiments

Security work with receipts.

A growing folder of synthetic incidents, detection logic, network-defense work, investigations, and the documentation that makes it reproducible.

Patch holding an Ethernet cable

Detection engineering

Suspicious Parent–Child Process

A synthetic endpoint chain designed to build and validate behavioral detection logic in Microsoft security tooling.

  • MDE
  • ADX
  • KQL

Network detection

Cross-Zone Lateral Movement

Firewall and endpoint telemetry combined to identify suspicious movement across security boundaries.

  • Sentinel
  • Palo Alto
  • MDE

Incident response

Synthetic Incident Series

AI-assisted faux datasets for practicing investigation, scoping, detection development, and technical reporting in public.

  • IR
  • Threat Hunting
  • Education

STATUS: Detailed case studies and repository links are being assembled. The lab is operational; the filing system is a work in progress.