Projects
This page separates existing lab exercises from projects still being built. I’ll add results only after testing them.
Security detection and investigation lab
Stage: active lab work
My security lab includes Elastic Security. Current detection and investigation exercises cover:
- Agent Spoofing: Multiple Hosts Using Same Agent.
- Failed logins.
- Suspicious process activity, including rundll32.
- Windows service creation.
- New DNS domains.
- The benign EICAR test file.
Each write-up will explain the alert logic, relevant event fields, investigation steps and what the evidence does or does not show.
Read-Only Security Alert Agent with Synthetic Logs
Stage: planned
The goal is to build a small assistant that helps an analyst investigate a test alert. It will use read-only access to a dedicated Elastic lab index and produce:
- A short summary linked to supporting events.
- An event timeline.
- Missing or conflicting evidence.
- Follow-up checks for a human analyst.
The project will use synthetic or lab-generated telemetry. The agent will not write to Elastic, isolate hosts, disable accounts or run response actions. I’ll test how it handles incomplete evidence and instruction-like text inside log fields.
AI and malware research
My MSc research examined image-based Android malware detection using deep learning. I’m building on that foundation as I study model evaluation and practical uses of AI in security. Future experiments will include the data source, evaluation method and limitations.