Ciso Tactical Threat Hunter
Current▪Use open-source research to develop threat hunt hypothesis for Advanced Persistent Threat (APT) groups and other malicious threat actors.▪Perform TTP based Cyber Threat hunts for 500K endpoints located throughout the global enterprise environment.▪Hunt suspicious behaviors through analysis of EDR data from Carbon Black Response, Carbon Black Detect, CrowdStrike, and Microsoft Defender Advanced Threat Protection as well as SIEM data.▪Examine process data and network activity for suspicious scripts, including PowerShell, Python, and WMIC for malicious use among many others. ▪Recommend threat mitigations and remediation's for malicious activities.▪Develop EDR queries for console detections used as alerts for SOC personnel.▪Developed, implemented, and maintained a “threat hunt lab”, an environment used to conduct malicious activity such as detonating malware and running various exploits/zero-days, stress testing security tool stack and detection rulesets. ▪Analyzed results from lab activity through security tool stack and created detection rules for any gaps found in EDR platforms.▪Conduct threat hunting activities through EDR and SIEM platforms▪Profile threat actors relevant to the business and map techniques and tactics ▪Work with BAAS tools to simulate adversary activities in a testing environment▪Solutioned and designed a threat hunting sandbox environment as a dev station to test and stress security stack and create/tune EDR rules