Detection Engineering & GRC

SIEM engineering with Sentinel & Wazuh, KQL threat hunting, ISO 27001, DORA, NIS2 compliance.

🚧 KQL detection rules, ISMS templates, and case studies coming soon.

Core Areas

SIEM & Threat Hunting

  • Microsoft Sentinel: analytic rules, workbooks, automation playbooks
  • Wazuh: agent configuration, custom decoders, active response
  • KQL query writing: advanced threat hunting, false positive tuning
  • Log analysis across Azure, Entra ID, on-prem endpoints

Vulnerability Management

  • Trivy (container and IaC scanning)
  • OpenVAS network scanning
  • Severity triage, CVSS scoring, remediation tracking

Threat Modeling

  • STRIDE methodology
  • Data flow diagramming
  • Risk register construction

GRC & Compliance

  • ISO 27001:2022 ISMS: risk register, SoA (93 controls), IR playbook
  • DORA Article 9 alignment
  • NIS2 Directive alignment
  • Morocco Law 05-20 & Law 09-08

Adversary Simulation & Detection Engineering Lab