Incident response · Security engineering · LondonExplore the connections ↓

Hello, I’m

Mohamad Kaimouz.

Investigate the intrusion.

Engineer the response.

Senior Cyber Security Analyst
UK Water Utility

SOC & incident responseKQL2 casesSOC & incident responseMicrosoft Defender for Endpoint2 casesSOC & incident responseMicrosoft Sentinel5 casesSOC engineeringServiceNow SecOps1 caseSOC engineeringSOAR2 casesSOC engineeringXSOAR1 caseDetection engineeringMITRE ATT&CK3 casesDetection engineeringAzure DevOps1 caseResponse automationPowerShell3 casesResponse automationDefender Live Response2 casesResponse automationCopilot Studio1 caseOffensive securityThreat modelling2 casesOffensive securityActive Directory3 casesOffensive securityOWASP2 casesSecurity engineeringKerberos1 caseSecurity engineeringNTLMv21 caseSecurity engineeringControl assurance1 caseSecurity leadershipSOC leadership1 caseSecurity leadershipAnalyst development1 caseSecurity leadershipMDR transition1 caseSoftware developmentPHP1 caseSoftware developmentMySQL1 caseSoftware developmentAWS EC21 caseLearning & recognitionDigital forensics1 caseLearning & recognitionRansomware research1 caseLearning & recognitionCryptography1 case

A few places to start

Experience, connected.

All cases ↗
UK Water Utility

Automate endpoint investigation and response

Response Automation / Incident Response Engineering

Built PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.

Read the story
UK Water Utility

Automate evidence collection for incident-response support

Response Automation / Evidence Collection

Automated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.

Read the story
UK Water Utility

From business risk to detection

Detection Engineering / Detection as Code

Built a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.

Read the story
UK Water Utility

Keeping response operational through an MDR transition

SOC Continuity & Service Leadership

Led SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.

Read the story
Growing MSSP with Offensive Services

Reconstruct a remote-support intrusion

SOC / Incident Response

I used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.

Read the story
Growing MSSP with Offensive Services

Technical oversight of an offensive security service

Offensive Security Leadership

Oversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.

Read the story
UK University / University in Lebanon

Fully funded study. Distinction in both degrees.

Academic Achievement & Community Leadership

Completed a fully funded BSc and MSc with Distinction, combining specialist security study with research into ransomware key management, a Philosophy minor and community leadership.

Read the story

Your exploration

Viewed history

Saved only in this browser.