Detection Engineering | Telemetry Architecture & Detection-as-Code | Application Security | DevSecOps
I design, validate, and automate high-fidelity detection logic and telemetry pipelines. My work focuses on bridging threat intelligence with software engineering principles, transforming adversary TTP research into tested, continuous Detection-as-Code (DaC) infrastructure.
| Category | Primary Focus & Tooling |
|---|---|
| Detection Logic | Sigma, YARA, KQL, SPL, Falco, Suricata |
| Telemetry & Logging | OS-level Telemetry (ETW, Sysmon, eBPF, Auditd), Log Pipelines |
| Automation & CI/CD | Detection Rule Linting, Unit Testing (Pytest), GitHub Actions |
| Validation & Hunting | Threat Emulation (Atomic Red Team), MITRE ATT&CK Mapping |
| Security Testing | Penetration Testing, Red Teaming, Purple Teaming |
- High-Signal Quality: Detection logic must provide actionable context and prioritize low false-positive rates over alert volume.
- Detection-as-Code: Rules are version-controlled, peer-reviewed, tested against telemetry datasets, and deployed via CI/CD.
- Telemetry-Driven: Effective coverage begins by engineering the underlying event streams before writing detection logic.
- Professional Identity:
the-d3fender/across technical platforms - Publications & Research: Research Files




