// case.studies
Case Studies
Outcome-focused write-ups of representative offensive and defensive work. Every case study is sanitized — no employer-specific detection logic, client data, private infrastructure, or exploitable detail is included.
Sanitized · lab / generalized evidence only
Bug Bounty & Web Application Security Research
A repeatable recon-to-report methodology for public bug bounty programs, focused on high-signal findings and clear, reproducible reports.
Read case study Web PentestWeb Application Penetration Testing Lab
A self-hosted lab for practicing the full exploitation chain end-to-end against intentionally vulnerable, legally testable targets.
Read case study DetectionDetection Rule Engineering (MITRE ATT&CK)
Authoring analytics mapped to MITRE ATT&CK to detect ransomware, lateral movement, and persistence — with attacker-informed tuning.
Read case study DetectionSOC Automation Pipeline
An automation pipeline that cut mean-time-to-notify for priority alerts to under two minutes with ticketing and endpoint response.
Read case study DetectionSIEM False-Positive Reduction
A structured tuning program that reduced SIEM false positives by ~40% while preserving detection coverage.
Read case study InfrastructureVulnerability Assessment & Hardening
Recurring assessment and CIS-based hardening across a large node estate, prioritized by CVSS and real business impact.
Read case study