I've spent 8+ years in security, most of it in detection and response: writing detections, hunting threats, running forensics, and serving as incident commander on high-impact incidents. I also build the security tools I want on hand during an investigation. The four security tools on this page are open source, tested, and green in CI, so you can read the code before you take my word for it.
|
lower average time to mitigate KQL over Sentinel and Defender |
time to acknowledge for the response rotation |
|
shorter median forensic case time about 6h to 3.5h with Python automation |
open-source Sigma rules 34 ATT&CK techniques and sub-techniques |
AI in the SOC, with a confidence gate. Paste a free-text incident into this open-source Python console and get a triage card back: incident class, severity, ATT&CK techniques, a playbook hint, and a case record. Its classifier is trained on 500,000 synthetic incidents, and it shows where an LLM helps triage and where it should stay out of the way. An analyst still moves every case from New to Closed.
- Classifier first. TF-IDF (5,000 features) plus 384-dimension sentence embeddings feed a logistic regression across 10 incident classes, from phishing and malware to insider threat and data exfiltration.
- LLM when unsure, by default. In Fallback mode, the default, the LLM runs only when classifier confidence is low. Off never calls it, and Override sends every event to the LLM. In the demo, a 45%-confidence call took about 1.4 s in the classifier and about 5.8 s in the LLM, and came back as Phishing (ATT&CK T1566 and T1598).
- Only known labels. The LLM can override the classifier only with schema-validated JSON and a known label, with synonyms normalized first. If it hedges, a forced second pass runs.
- Your model, your keys. Anthropic, OpenAI, Hugging Face, or local llama.cpp, swappable per session, with a fallback when a key is missing.
- Built for the analyst. Regex IOC extraction for 10 indicator types, VirusTotal enrichment with your own key, and one-click pivots to AbuseIPDB, Shodan, and GreyNoise.
- Hunt and track. A hunt page with Lucene-style queries such as
mitre:T1566 AND last:24h, case timelines with notes and tags, and CSV batch triage up to 500 rows.
Kill-chain view across 13 of 14 ATT&CK Enterprise tactics · 78 tests, CI green
The live app sleeps when idle: click wake and give it a moment. The docs site is always up.
I have served as senior incident commander for high-impact security incidents and run every stage of the response:
Triage → Containment → Eradication → Recovery → Root cause
- Malware, ransomware, and data protection incidents: recognized as incident commander for all three, and led ransomware eradication and recovery.
- Briefings people can act on: delivered risk assessments and remediation guidance to engineers and leadership.
- Identity-aware investigations: correlated endpoint, network, identity, and behavioral sources to rebuild multi-stage activity.
- Threat hunting: led enterprise threat hunting and network forensic analysis, and built the Splunk dashboards and Python automation behind it.
- For the next responder: wrote the investigation playbooks and response baselines they start from.
- AI in my own casework: used LLMs in production to summarize unstructured case data, triage events, draft investigation notes, and pull IOCs, timestamps, and actor patterns out of free text.
205 tests across the four security tools, CI green on all four.
| Function | At work, and in public code you can read |
|---|---|
| Detection as code | Python detections in Panther, version controlled and peer reviewed, over high-scale fintech telemetry · public: 20 Sigma rules in ScenarioKit |
| SIEM and query | Microsoft Sentinel, Splunk, Panther, KQL, SPL, and SQL. Made Snowflake monitoring queries about 20% faster for the on-call rotation. |
| Endpoint | Microsoft Defender telemetry · public: macOS persistence and code-signing audit in macos-trust |
| Cloud and containers | Daily CVE triage for Kubernetes containers and images; better SQL joins and filters saved about 2 hours per investigation · public: guardrails for bots and AI agents acting on infrastructure in policyforge |
| Hunting and forensics | Enterprise threat hunting · network forensics · Splunk dashboards · Python artifact collection, log parsing, and enrichment · public: Lucene-style search over triaged cases in AlertSage |
| AI in the SOC | LLMs in production for case summaries, IOC extraction, and event triage · public: confidence-gated LLM escalation in AlertSage |
| Reporting | Findings turned into clear next steps for engineering and security leaders · public: SARIF 2.1.0 for GitHub code scanning, plus JSON and HTML reports, in macos-trust |
| Languages | Python · Go · Swift · KQL · SPL · SQL · Monkey C |
Work versus public code: the Panther, Sentinel, Defender, Splunk, Snowflake, and Kubernetes work above comes from my day jobs and isn't public. The repos on this page are the part you can inspect today. Also: two years managing an enterprise information security governance and risk program.
Side projects built with the same habits: measure it, test it, ship it.
|
☀️ SolarHarvestMonkey C · Garmin Connect IQ · live on the Connect IQ Store Connected-device engineering on tight hardware. One codebase runs on 17 Garmin device targets (22 solar watch models), 3 Connect IQ API generations, and 3 screen sizes. It fits the 128 KB data-field limit on the tightest devices. It measures battery drain and solar gain from the watch's own 1% battery steps and records 19 developer FIT fields to every activity. 112 unit tests across device tiers · 7 pages · no network calls |
- 📚 KoNotes: local-first reading analytics with local embeddings, clustering, and LLM chat, plus a 7-subcommand CLI. 645 tests.
- 🏀 Hooplytics: NBA player models tested on later games they never saw (R² 0.615 for combined points, rebounds, and assists). A model is saved only if it passes an R² check. 30 tests.
Happy to compare notes on detection engineering, incident response, or putting LLMs to work in triage.









