Hands-on malware reverse-engineering, production SIEM correlation rules, and zero-day threat notifications curated for security engineers & threat analysts.
Extracting hidden PE payloads, unhooking API hooks, and parsing process memory dumps from active infection vectors.
Building high-fidelity SPL queries to detect suspicious IAM role assumption and cross-account privilege escalation.
Pattern matching techniques against layered string encoding, byte sequences, and AST syntax trees.
Setting up serverless Lambda triggers to isolate compromised EC2 instances within seconds of alert firing.