DETECTION / ENGINEERING

Detection Engineering Portfolio

Detection engineering work spanning attack simulation, custom Wazuh rules, telemetry validation and MITRE ATT&CK mapping.

04Evidence areas
RULESDetection focus
LABControlled validation
ATT&CKMapped techniques

Evidence

Linked source material
01

Attack Simulation & Detection Lab

Controlled attack simulations with custom Wazuh detections and validation evidence.

SimulationWazuhATT&CK
View evidence →
02

Wazuh Detection Engineering

Custom detection rules, event matching and investigation workflows.

WazuhRulesSIEM
View evidence →
03

Windows / Sysmon Telemetry

Endpoint telemetry used to validate detection logic and investigate process activity.

SysmonWindowsTelemetry
View evidence →
04

Detection Validation

Documented validation from signal generation through alert review, ATT&CK mapping and improvement.

ValidationTuningATT&CK
View evidence →

Evidence integrity

Scope & limitations
The portfolio distinguishes controlled laboratory validation, synthetic or offline material, and methodology/architecture work. Laboratory scenarios are not presented as production incidents or client engagements.