Skip to main content
Joshua Clarke

About Joshua Clarke

Eight years, one question: how did they get in?

I'm a Senior Cyber Security Analyst at Microsoft, currently focused on Azure fraud and abuse threat hunting. I combine telemetry-led investigation with a builder mindset, creating tooling and workflows that help security teams move faster.

Cheltenham, United KingdomMicrosoft security operations
01
8+
Years in Cyber Defence
02
4K+
YouTube Subscribers
03
8+
Educational Videos
04
192K+
Total Views

Investigation depth with delivery discipline.

Four connected capabilities shaped by hands-on security operations, engineering collaboration and practical education.

01

Threat hunting and platform abuse

Develop hypotheses, correlate Azure telemetry and turn ambiguous signals into actionable findings for detection, enforcement and disruption.

02

Cloud forensics and incident response

Investigate complex events across Azure, Microsoft 365, Gaming and enterprise environments with repeatable forensic workflows.

03

Analyst tooling and automation

Build practical PowerShell, Python and browser-based tooling that reduces repetitive work and improves investigation consistency.

04

Knowledge transfer

Translate technical findings into clear recommendations, specialist training and practical cybersecurity education.

From service desk to Azure threat hunting.

The progression has been deliberate: learn the systems, work the investigations, improve the workflow, then teach the next analyst.

Joshua Clarke in a casual black shirt
2013

Enterprise support

Customer service leadership and IT service desk operations at John Lewis Partnership.

2018

Security operations

Managed detection, IDS triage and AWS incident response at Alert Logic.

2019

MSSP investigation

Client monitoring and response using LogRhythm, Carbon Black and CrowdStrike at Context.

2020

Multi-cloud consulting

Threat-led protective monitoring across AWS and Azure at Accenture.

2021

Microsoft security

Incident response, cloud forensics and analyst tooling across global environments.

2025

Azure threat hunting

Fraud, abuse and adversarial platform investigations across large-scale cloud telemetry.

Tooling that changes how the work gets done.

Impact 01

Hours to minutes

Serverless forensic investigation platform

Designed an in-region disk forensics capability that became a primary SOC workflow for globally distributed investigations.

Impact 02

Set and monitor

Compliance and preservation automation

Built PowerShell automation that reduced bulk compliance work from hours or a full day to a monitored process.

Impact 03

Faster response

Priority case notification tooling

Created a Chrome extension integrated with ServiceNow to surface high-priority cases and launch one-click workflows.

Education and credentials

BSc Ethical Hacking and Network Security

Coventry University

CompTIA CySA+AZ-900AZ-500SC-200SC-300SC-400

Investigation toolkit

Tools used to investigate and automate.

KQLPowerShellPythonJavaScriptAzureMicrosoft 365Microsoft DefenderSIEMEDRSnort

Follow the work as it develops.

New investigations, practical labs, videos and community conversations across the platforms you already use.