Josh Strickland
DE&TH • Cloud Security

I hunt adversaries.

Threat Hunting • Detection Engineering • Cloud Security

I investigate security activity and respond to incidents, then use what I find to improve cloud controls, detections, and automation. I'm a Security Analyst II at Garner Health.

Josh
0
EDR Platforms Hunted
0
Custom Detections
0
Certifications

Threat Hunting, Detection Engineering, and Cloud Security.

Threat Hunting

Hypothesis-driven work across endpoint, cloud, and identity telemetry. I look for suspicious behavior that existing controls and detections miss.

Detection Engineering

I turn hunt findings and incident patterns into durable detections, tuned rules, and investigation workflows.

Cloud Security

I investigate cloud activity, work through high-volume security data, and build controls and automation around modern infrastructure.

Things I've Actually Found

Secnap

ClickFix Attack via Callstack Analysis

Caught a ClickFix attack through callstack analysis. Explorer.exe with shell32.dll was spawning untrusted processes. Stopped it before NetSupport RAT could deploy.

Red Canary

2-Month VPN Compromise

Found a threat actor sitting in a customer's VPN for two months, undetected, running AD brute force. Built a recurring hunt to cover the gap.

View All Hunts

What I Work With

AWS Azure GCP Microsoft 365 Google Workspace LimaCharlie CrowdStrike SentinelOne Microsoft Defender Carbon Black Palo Alto Cortex Wazuh Velociraptor Fibratus (ETW) Sigma Rules MITRE ATT&CK Microsoft Entra ID Active Directory Python Jupyter Pandas PowerShell Linux

Want to talk shop?

Always down to connect about threat hunting, detection engineering, cloud security, or anything security.

Get In Touch