Cyber Warfare Operator
CurrentOperates as part of a highly skilled team of cybersecurity experts to conduct Defensive Cyberspace Operations to ensure the security of the infrastructure of the Air Force and associated organizations.Hunts for indicators of malicious activity, particularly from APT actors, by hunting for known TTPs.Utilized SIEM and visualization tools to investigate IT/OT networks for APT activity.Analyzed artifacts from network devices and endpoints such as windows logs, network packets, process listings and more.Configured/deployed tools such as ELK to continuously monitor a network and ingest data from other sources.Created scripts in powershell for facilitate information collection in event tools were not working.Compiled a list of fix actions/best practices based on DOD and commercial standards.Participate in internal and commercial made training events between missions to continue developing cyber hunting skills through experience and repetition.