Tempe, Arizona, United States
Set up an OS instrumentation framework for Windows and Ubuntu systems using open source softwares like Osquery and Kolide Fleet.
Developed and tested SQL queries to monitor and extract logs from osquery indicating suspicious behavior, anomalies in line with MITRE analytics.
Collaborated with the Infrastructure team to develop analytics that use network logs to capture suspicious activities at packet level.
Tools and technologies: Mitre ATT&CK framework, Osquery, Fleet, Suricata, Tcpdump, Pktmon.