I'm a SOC & Security Engineer based in Abu Dhabi, building and operating enterprise and government SOC environments on the Microsoft security stack β Sentinel, Defender XDR and Entra ID β across Azure and hybrid estates.
I like the engineering half of security: onboarding log sources properly, writing KQL that holds up in production, and tuning noise out of the pipeline so analysts spend their time on the alerts that matter. A background in penetration testing keeps the attacker's view in every detection I write.
| β±οΈ 4 days | Critical infrastructure onboarded against a 10-day scope |
| πΈ 30β40% | Monthly log-ingestion reduction across client tenants β detection coverage intact |
| β Zero | Post-deployment rework on a full government SOC build |
- π‘οΈ Engineering SOCs and detection content at Ansen Technologies (multi-client, SLA-driven)
- π Studying for SC-500 (Azure Security Engineer) and SC-401 (Information Security Administrator)
- π§ͺ Building TFII, CertPrep and Kestrel in the open
| Project | What it is | Stack |
|---|---|---|
| TFII | Self-hosted threat-intel workspace that pulls public feeds and CVE data into one place and shows its reasoning β corroborated confidence, honest geolocation, bulk IOC triage, STIX 2.1 / TAXII 2.1, CISA KEV + EPSS. | Python FastAPI React PostgreSQL Docker |
| CertPrep | Exam prep for SC-200 / SC-401 / SC-500 with a simulated Defender XDR + Sentinel + Azure lab β a real KQL engine and a full intrusion hidden in the telemetry. 534 tests. | Next.js Tailwind Prisma Postgres |
| Sentinel Workbooks | Weekly SOC reporting workbook: incident trend, ingestion volume & cost, top log sources, MITRE tactic coverage, blocked IPs, failed-login leaders. | Sentinel KQL Azure Workbooks |
| Kestrel | Tasker-grade automation & Modes for any Android phone. Turns Shizuku's perishable shell authority into permanent grants that survive reboots. | Kotlin Compose Shizuku |
| GetFit | 100% offline, no-account Android workout tracker with a 1,300+ exercise library. | Kotlin Jetpack Compose Room |
| Neoteric OS | Minimal custom Android ROM focused on UI/UX and performance β AOSP-level device bring-up, vendor/hardware layers and framework forks. | AOSP C++ SELinux |
Threat intel, IR & vulnerability management
Six habits that show up in my day job and my side projects alike β each with the receipts:
Show your reasoning Β· Fail loudly, never silently Β· Tune for signal, not volume Β· Test the claims Β· Write it down so others can run it Β· Private by default
βΆ See them in practice on the portfolio
Want to compare notes on Sentinel, KQL or detection engineering? Say hello from the portfolio.


