I like building projects that help security teams understand threats better - bridging offensive knowledge with defensive implementation.
Currently building C2 Workbench - a platform analyzing 200+ command and control frameworks to help defenders write better detections.
Questions I'm pondering:
- How do we scale detection engineering in resource-constrained teams?
- What's the right balance between automation and analyst judgment?
- How can we better measure detection coverage without gaming metrics?
Interested in collaborating on:
- Threat detection and response automation
- Identity security and access management
- Security posture assessment tools
- MITRE ATT&CK implementation


