Logged as detections, because that's how a SOC would triage them: each one flags a real capability, with the tooling and technique behind it.
DET-002High confidence
Authentication Anomaly Detection & Risk Scoring Engine
MSc dissertation project: a Python risk-scoring engine using Isolation Forest and LSTM models to flag anomalous login behaviour — normal, suspicious, and brute-force scenarios — with detections mapped to MITRE ATT&CK tactics and techniques. Supervised by Dr. Eckhard Pfluegel, in collaboration with industry partner David Douglas.
PythonIsolation ForestLSTMRisk Scoring
Credential AccessDetection Engineering
DET-001Ongoing
Home SOC & SIEM Lab
Self-built lab for SOC analyst portfolio work: Windows Server 2022 and endpoint telemetry via Sysmon (SwiftOnSecurity config), ingested into Splunk Enterprise for log analysis, detection engineering, and incident triage practice.
Splunk EnterpriseSysmonWindows Server 2022VMware Workstation
Log AnalysisEndpoint Telemetry
DET-003Verified
AI-Powered Vulnerability Scanner
Modular Python tool built for postgraduate coursework: scanning, CVE lookup, an LLM-based triage agent (Groq / LLaMA 3.3 70B), and automated reporting — tested against live scan targets, with full architecture documentation and a risk register.
PythonCVE LookupLLM Triage AgentAutomated Reporting
View repository →
DET-004Informational
ISO 27001 ISMS Gap Assessment
GRC internship deliverable: asset register, ISO 27001 gap assessment, and security policy documentation built around a simulated FinTech environment — grounding technical detection work in governance and compliance context.
ISO 27001Asset RegisterPolicy DocsGRC