Suspicious cloud token use
Mapped identity abuse to ATT&CK, wrote detection logic, tested false positives and documented tuning notes.
Labs, SIEM logic and response workflows presented with context: what broke, what I tested, what I learned.
cloud_token_anomaly()
Can investigate, tune and explain.
Mapped identity abuse to ATT&CK, wrote detection logic, tested false positives and documented tuning notes.
Built a clear investigation path from alert to enrichment to analyst note.
Moved beyond screenshots: impact, evidence, fix and retest status.
XSIAM, Wazuh, Linux, Python, Git, Wireshark.
ATT&CK mapping, alert tuning, enrichment, report writing.
Queries, screenshots, architecture diagrams and lessons learned.