Enhanced scalable logging and detection capabilities by optimizing Elastic Stack SIEM for diverse data sources.
Built and implemented automated detection mechanisms leveraging threat intelligence and MITRE ATT&CK TTP-based modeling in SIEM and XDR.
Automated Microsoft Sentinel and Defender XDR playbooks using Azure Logic Apps and integrated dynamic Teams Message Cards for multi-alert summarization and evidence toggling.
Developed a multi-metric scoring system (CVSS, SSVC, EPSS, CKEV) to prioritize vulnerability management strategies.