Security operations and detection engineering practitioner focused on practical tooling, reliable detections, and clear incident response.
I work as an Engineer II in Computer Operations Support at Verisign, where I support phishing and threat triage, incident response, and Splunk detection dashboards. I also build detection-engineering and AI-assisted security operations projects in a self-hosted Proxmox lab.
I am pursuing a B.S. in Cybersecurity at the University of Maryland Global Campus.
- wazuh-ai-siem: A Wazuh-based SIEM and detection-engineering lab with custom MITRE ATT&CK-mapped rules, local-LLM threat triage, natural-language threat hunting, and automated response workflows.
- siem-detect: A dependency-light Sigma detection engine for syslog, Nginx, authentication, EVTX JSON, and CloudTrail events.
- phishing-analyzer: A Python phishing-analysis toolkit for
.emlparsing, email-authentication checks, IOC extraction, attachment scanning, risk scoring, threat-intelligence enrichment, and STIX 2.1 export. - phish-triage: A phishing-email triage toolkit with deterministic parsing, optional VirusTotal and AbuseIPDB enrichment, and Splunk SPL and Sigma detections mapped to MITRE ATT&CK.
- bob-page: A live profile and status page for Bob, an autonomous AI agent, deployed on Cloudflare Pages and Workers.
- Security alert and phishing triage
- Detection engineering with Sigma, Splunk, Wazuh, and MITRE ATT&CK
- Security automation and incident-response workflows
- Python, Bash, and PowerShell tooling
- Self-hosted infrastructure with Proxmox, Docker, Linux, pfSense, and Suricata




