Skip to content

Projects

Case studies from my leadership, architecture and investigation work, followed by tools and integrations.

Building a Compromise-Assessment Capability and Cordon

I built a compromise-assessment method and an OpenShift forensic collector that works without creating debug pods.

Capability lead, architect and hands-on engineer · 2025

Read case study

Building ThreatOps-CTI and an Operational MISP Program

I built a pipeline that filters open-source intelligence for the organization, then sends the useful material to MISP, hunting and detection workflows.

CTI program lead and engineer · 2025

Read case study

Multi-Tenant Elastic Security Architecture

I designed a private-cloud Elastic platform that keeps client data separate even when different clients use the same private subnets.

Security architect and engineer · 2026

Read case study

Building and Operationalizing a SOC for a Digital Bank

I helped turn a deployed SIEM and partial log onboarding into a working SOC with case handling, detection, reporting and analyst processes.

SOC operations lead and engineer · 2024

Read case study

Evolving a Monitoring-Focused SOC into a Multi-Disciplinary Cyber Defense Service

I grew a multi-client SOC team and added incident response, DFIR, compromise assessment, architecture and engineering work.

Cyber defense lead · 2026

Read case study

Test-Driven Detection Engineering Framework

A test-first workflow for taking detection logic from Sigma to working QRadar, Splunk and Elastic queries.

Detection engineer · 2025

Read case study

QRadar API and Syslog Middleware

I built middleware that reads an API, normalizes the data and sends usable events to QRadar through syslog.

Integration engineer · 2024

Read case study

Argus CTI

An automated pipeline for collecting RSS threat feeds, applying CTI tags, filtering relevant entries and creating structured MISP events.

Project overview · Related article

API to QRadar middleware

Moving events from an API into QRadar through a syslog middleware layer.

Project overview · Related article

MISP deployment

Deployment notes for a threat intelligence platform used to organize and share intelligence.

Project overview · Related article

BookStack

Documentation platform setup for organizing technical knowledge and procedures.

Project overview · Related article

EDR assessment

April 2024–January 2025. Assessing endpoint detection, incident response, forensic investigation capabilities, integrations and performance. The assessment considers operational suitability and opportunities to improve endpoint defenses.

SOAR workflows with TheHive

Integrating TheHive with Cortex, MISP, QRadar, threat intelligence platforms, email, Teams and n8n. Python scripts support analyst KPIs, SLA compliance, detection and handling times, and automated SOC shift reports.

Hyper Coding Zone

An education system for web-development learning on Android and the web, associated with Modern Academy Maadi. It offers structured learning tracks with exams and a separate mode for browsing courses freely.