Scroll to top

Incident Response & Threat Hunt

Network Security Project
Cybersecurity Implementation

Project Overview

An organization (confidential) called me in after signs of a suspected intrusion, needing to know quickly whether an adversary was inside, how far they had reached, and how to get them out. I led the response end to end: rapid triage to establish scope, SOC/SIEM-driven threat hunting guided by MITRE ATT&CK, then containment and eradication once the footprint was understood. Because the adversary was potentially still active, every move balanced speed against the need to preserve forensic evidence and keep the business running. I reconstructed a forensic timeline of exactly what happened and when, then hardened detections so the same intrusion path could not be walked again unseen.

Challenges

  1. Establish the true scope of the intrusion when the initial picture was uncertain.
  2. Operate against a possibly still-active adversary without tipping them off prematurely.
  3. Keep the business running while response, containment and eradication were underway.
  4. Preserve forensic evidence intact for later analysis and any potential legal follow-up.
  5. Overcome pre-existing detection gaps that had let the activity go unnoticed.

Approach

  1. Performed rapid triage and scoping to size the incident and prioritize immediate action.
  2. Ran ATT&CK-guided threat hunting across SIEM and endpoint telemetry to locate the adversary.
  3. Executed coordinated containment and eradication to remove the foothold safely.
  4. Reconstructed a forensic timeline to establish what happened, when and how.
  5. Engineered new detections and alerting to prevent the same intrusion recurring.