At Concentrix, I handle high- and critical-severity MDR incidents across 500,000+ endpoints, from triage through containment, remediation, and closure. I use XQL to investigate telemetry, reconstruct attack timelines, and hunt for activity mapped to MITRE ATT&CK.
I'm building ATTACKTRACE, a SOC investigation and threat-intelligence platform that turns security telemetry into evidence-backed incidents. It correlates events, presents investigation timelines and attack graphs, and links findings to their source evidence.

