🚧 KQL detection rules, ISMS templates, and case studies coming soon.
Core Areas
SIEM & Threat Hunting
- Microsoft Sentinel: analytic rules, workbooks, automation playbooks
- Wazuh: agent configuration, custom decoders, active response
- KQL query writing: advanced threat hunting, false positive tuning
- Log analysis across Azure, Entra ID, on-prem endpoints
Vulnerability Management
- Trivy (container and IaC scanning)
- OpenVAS network scanning
- Severity triage, CVSS scoring, remediation tracking
Threat Modeling
- STRIDE methodology
- Data flow diagramming
- Risk register construction
GRC & Compliance
- ISO 27001:2022 ISMS: risk register, SoA (93 controls), IR playbook
- DORA Article 9 alignment
- NIS2 Directive alignment
- Morocco Law 05-20 & Law 09-08