Threat Hunting • Detection Engineering • Cloud Security
I investigate security activity and respond to incidents, then use what I find to improve cloud controls, detections, and automation. I'm a Security Analyst II at Garner Health.
Hypothesis-driven work across endpoint, cloud, and identity telemetry. I look for suspicious behavior that existing controls and detections miss.
I turn hunt findings and incident patterns into durable detections, tuned rules, and investigation workflows.
I investigate cloud activity, work through high-volume security data, and build controls and automation around modern infrastructure.
Caught a ClickFix attack through callstack analysis. Explorer.exe with shell32.dll was spawning untrusted processes. Stopped it before NetSupport RAT could deploy.
Found a threat actor sitting in a customer's VPN for two months, undetected, running AD brute force. Built a recurring hunt to cover the gap.