Security Operations

Hi, I'm Callum.Security Consultant

Threat HuntingDetection EngineeringIncident InvestigationThreat Intelligence

I work in a Microsoft security-based SOC, mostly in Sentinel, Defender and KQL. In my spare time I research cloud attack techniques and build tooling.

// about

What I do

KQL
Building advanced threat hunting queries and analytic rules.
Threat Research
Researching offensive threats to strengthen defensive security.
Homelab
Managing a technical homelab for security research and self-hosting!

// journey

How I got here

  1. 01

    Learning by breaking things

    Got started with CTFs on TryHackMe and Hack The Box. They gave me hands-on exposure to programming, operating systems, and both the offensive and defensive sides of security.

  2. 02

    Going deeper into systems

    Joined a Cloud Engineering apprenticeship, building a solid foundation in cloud platforms, operating systems and IT infrastructure, with time on the service desk solving real problems for real users.

  3. 03

    Working in security

    Started my security career as a 24/7 SOC Analyst, investigating alerts and responding to incidents around the clock. I then moved into a Security Consultant role to go deeper into detection engineering, threat hunting and security research.

// projects

Research & builds

Living Off The Cloud: Azure for covert C2
In progress
Research paper examining how attackers can abuse legitimate Azure services for stealthy command-and-control traffic, and what defenders can do to detect it.
ResearchAzureDetection

// contact

Get in touch

Always happy to talk detection engineering, cloud security or anything SOC-related. The best way to reach me is through X.