Projects
Case studies from my leadership, architecture and investigation work, followed by tools and integrations.
Building a Compromise-Assessment Capability and Cordon
I built a compromise-assessment method and an OpenShift forensic collector that works without creating debug pods.
Capability lead, architect and hands-on engineer · 2025
Building ThreatOps-CTI and an Operational MISP Program
I built a pipeline that filters open-source intelligence for the organization, then sends the useful material to MISP, hunting and detection workflows.
CTI program lead and engineer · 2025
Multi-Tenant Elastic Security Architecture
I designed a private-cloud Elastic platform that keeps client data separate even when different clients use the same private subnets.
Security architect and engineer · 2026
Building and Operationalizing a SOC for a Digital Bank
I helped turn a deployed SIEM and partial log onboarding into a working SOC with case handling, detection, reporting and analyst processes.
SOC operations lead and engineer · 2024
Evolving a Monitoring-Focused SOC into a Multi-Disciplinary Cyber Defense Service
I grew a multi-client SOC team and added incident response, DFIR, compromise assessment, architecture and engineering work.
Cyber defense lead · 2026
Test-Driven Detection Engineering Framework
A test-first workflow for taking detection logic from Sigma to working QRadar, Splunk and Elastic queries.
Detection engineer · 2025
QRadar API and Syslog Middleware
I built middleware that reads an API, normalizes the data and sends usable events to QRadar through syslog.
Integration engineer · 2024
Argus CTI
An automated pipeline for collecting RSS threat feeds, applying CTI tags, filtering relevant entries and creating structured MISP events.
API to QRadar middleware
Moving events from an API into QRadar through a syslog middleware layer.
MISP deployment
Deployment notes for a threat intelligence platform used to organize and share intelligence.
BookStack
Documentation platform setup for organizing technical knowledge and procedures.
EDR assessment
April 2024–January 2025. Assessing endpoint detection, incident response, forensic investigation capabilities, integrations and performance. The assessment considers operational suitability and opportunities to improve endpoint defenses.
SOAR workflows with TheHive
Integrating TheHive with Cortex, MISP, QRadar, threat intelligence platforms, email, Teams and n8n. Python scripts support analyst KPIs, SLA compliance, detection and handling times, and automated SOC shift reports.
Hyper Coding Zone
An education system for web-development learning on Android and the web, associated with Modern Academy Maadi. It offers structured learning tracks with exams and a separate mode for browsing courses freely.