At LTIMindtree, I build KQL-based EDR detections mapped to MITRE ATT&CK, analyse alerts across Windows, Linux, macOS, and Android, and research active threat campaigns. I fine-tune behavioral signatures and detection graders to reduce false positives while keeping coverage current with real-world threats.
Previously at Connectwise, I contained and mitigated five coordinated ransomware campaigns, reduced SOC alert noise by over 30%, and helped integrate security tooling into a unified workflow. I also mentor SOC analysts and bring hands-on experience across Microsoft Sentinel, SentinelOne, Microsoft Defender XDR, malware analysis, IOC investigation, and incident response.
