Threat hunting and platform abuse
Develop hypotheses, correlate Azure telemetry and turn ambiguous signals into actionable findings for detection, enforcement and disruption.
Eight years, one question: how did they get in?
I'm a Senior Cyber Security Analyst at Microsoft, currently focused on Azure fraud and abuse threat hunting. I combine telemetry-led investigation with a builder mindset, creating tooling and workflows that help security teams move faster.
Four connected capabilities shaped by hands-on security operations, engineering collaboration and practical education.
Develop hypotheses, correlate Azure telemetry and turn ambiguous signals into actionable findings for detection, enforcement and disruption.
Investigate complex events across Azure, Microsoft 365, Gaming and enterprise environments with repeatable forensic workflows.
Build practical PowerShell, Python and browser-based tooling that reduces repetitive work and improves investigation consistency.
Translate technical findings into clear recommendations, specialist training and practical cybersecurity education.
The progression has been deliberate: learn the systems, work the investigations, improve the workflow, then teach the next analyst.

Customer service leadership and IT service desk operations at John Lewis Partnership.
Managed detection, IDS triage and AWS incident response at Alert Logic.
Client monitoring and response using LogRhythm, Carbon Black and CrowdStrike at Context.
Threat-led protective monitoring across AWS and Azure at Accenture.
Incident response, cloud forensics and analyst tooling across global environments.
Fraud, abuse and adversarial platform investigations across large-scale cloud telemetry.
Hours to minutes
Designed an in-region disk forensics capability that became a primary SOC workflow for globally distributed investigations.
Set and monitor
Built PowerShell automation that reduced bulk compliance work from hours or a full day to a monitored process.
Faster response
Created a Chrome extension integrated with ServiceNow to surface high-priority cases and launch one-click workflows.
Education and credentials
Coventry University
Investigation toolkit
New investigations, practical labs, videos and community conversations across the platforms you already use.