Security Researcher
2026 to presentIndependent
Hands-on detection engineering, network forensics, and adversary TTP analysis. Mapped a full MITRE ATT&CK kill chain for a dual-C2 ransomware sample in under 48 hours, maintains a containerised Linux DFIR lab in Docker, and publishes interactive malware-traffic write-ups alongside systems work on hypervisors and geospatial anomaly detection.
