All cards in this section are viewed.
Hello, I’m
Mohamad Kaimouz.
Investigate the intrusion.
Engineer the response.
Senior Cyber Security Analyst
UK Water Utility
Ask my portfolio
Ask about my work.
Skills, achievements, technical detail. Follow the evidence.
How this works
When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.
KQL, Sentinel, Defender and on-prem AD. Follow a domain into the work.
A few places to start
Experience, connected.
All cards in this section are viewed.
Automate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storyFrom business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyKeeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyReconstruct a remote-support intrusion
SOC / Incident ResponseI used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storyFully funded study. Distinction in both degrees.
Academic Achievement & Community LeadershipCompleted a fully funded BSc and MSc with Distinction, combining specialist security study with research into ransomware key management, a Philosophy minor and community leadership.
Read the storyA few places to start
Experience, connected.
All cards in this section are viewed.
Automate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storyFrom business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyKeeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyReconstruct a remote-support intrusion
SOC / Incident ResponseI used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storyFully funded study. Distinction in both degrees.
Academic Achievement & Community LeadershipCompleted a fully funded BSc and MSc with Distinction, combining specialist security study with research into ransomware key management, a Philosophy minor and community leadership.
Read the storySOC & incident response
Investigate the intrusion
Investigate identity compromise, malware and lateral movement through EDR telemetry, Microsoft 365 audit logs, VPN sessions and Windows artefacts. Follow the evidence from alert triage to incident scoping and response.
All cards in this section are viewed.
Trace compromised VPN access into the network
Network & Identity Incident ResponseI correlated NTLM logons with VPN address assignments and network activity to scope two compromised accounts, then extended host investigation with Velociraptor.
Read the storyFollow a mailbox compromise through the account
Identity & Email Incident ResponseI reconstructed Microsoft 365 account compromise through Azure sign-in logs, Office compliance records and browser history, then investigated unauthorised MFA registration and inbox rules.
Read the storyUnpack a staged PowerShell malware chain
Malware Analysis / Incident ResponseI deobfuscated a PowerShell loader and traced MSBuild, C2 and Autorun behaviour through controlled analysis, then checked which stages appeared in client telemetry.
Read the storyReconstruct a remote-support intrusion
SOC / Incident ResponseI used Windows Prefetch, Quick Assist logs and VirusTotal/ANY.RUN context to reconstruct a NetSupport intrusion after early endpoint telemetry was unavailable.
Read the storyRead the operation behind the OT alert
OT Security Monitoring & InvestigationInvestigated OT incidents against known backup behaviour and helped define the telemetry and response ownership around Claroty and Sentinel monitoring.
Read the storySOC leadership and incident response across client environments
MSSP Security Operations & Incident ResponseLed SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.
Read the storyCNI SOC leadership and investigation standards
Security Operations LeadershipOnboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.
Read the storyAutomate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storySOC engineering
Keep response working
Connect Microsoft Sentinel, ServiceNow Security Incident Response and XSOAR through incident lifecycle requirements, controlled integration testing and operational handovers for an MDR service.
All cards in this section are viewed.
Keeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyKeep incident meaning intact across platforms
Security Operations EngineeringValidated nine bidirectional Sentinel–ServiceNow closure scenarios and defined incident, entity and escalation requirements across the SIEM/SOAR workflow.
Read the storyCreate realistic security incidents on demand
Automation / Security Operations EngineeringBuilt a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.
Read the storyTurn incident records into executive briefings
Reporting Automation / Security Operations EngineeringAutomated executive incident-of-note slides linking the security event, the weakness exploited and the follow-up actions required.
Read the storyDetection engineering
From business risk to detection
Connect threat modelling, MITRE ATT&CK and telemetry requirements to Sentinel use cases and versioned detection logic. Explore the detection lifecycle and the analysis that turns Red Team observations into a prioritised backlog.
All cards in this section are viewed.
From business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyTurn Red Team findings into engineering priorities
Security Engineering / Detection Use CasesMapped 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering items, with ATT&CK mappings and telemetry dependencies.
Read the storyResponse automation
Automate the repeatable
Build repeatable response workflows with PowerShell, KQL, Defender Live Response, Copilot Studio and Power Automate: endpoint investigation, evidence collection and Sentinel test incidents for ServiceNow SecOps. Explore reporting and reconnaissance automation too.
All cards in this section are viewed.
Automate endpoint investigation and response
Response Automation / Incident Response EngineeringBuilt PowerShell and KQL investigation tools around Defender for Endpoint, and enabled Microsoft Defender’s native automated account containment.
Read the storyAutomate evidence collection for incident-response support
Response Automation / Evidence CollectionAutomated incident-response collector deployment, execution and evidence upload through Defender Live Response for Windows and Linux endpoints.
Read the storyCreate realistic security incidents on demand
Automation / Security Operations EngineeringBuilt a Teams-triggered Power Automate workflow that creates curated Sentinel incidents for ServiceNow SecOps integration tests and resets the rule automatically.
Read the storyTurn incident records into executive briefings
Reporting Automation / Security Operations EngineeringAutomated executive incident-of-note slides linking the security event, the weakness exploited and the follow-up actions required.
Read the storyOrganisation-led reconnaissance automation
Offensive Security AutomationI built an organisation-name-driven reconnaissance tool for discovery and lightweight checks, alongside offensive automation in Python, Bash and PowerShell.
Read the storyOffensive security
Think like an adversary
Assess external attack surfaces, on-prem Active Directory, web applications and cloud configurations. Explore assumed-breach testing, physical assessments and threat modelling that connects an intrusion path to the controls a client needs.
All cards in this section are viewed.
Hands-on application and infrastructure testing
Offensive Security AssessmentI delivered application, Active Directory and infrastructure assessments, with source-code review, simulated phishing and payload work using LOLBins and DLL hijacking.
Read the storyScoping assessments around the client's threats
Offensive Scoping & Threat ModellingI scoped external, internal and assumed-breach assessments around attack-surface discovery, Active Directory, email defences and EDR/network visibility, informed by incident-response work.
Read the storyTest physical and network boundaries at client workplaces
Physical Security AssessmentI tested hotel guest/TV network segmentation, restricted-area access and employee QR scenarios, including Raspberry Pi placement tests for a controlled C2 connection.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storyOrganisation-led reconnaissance automation
Offensive Security AutomationI built an organisation-name-driven reconnaissance tool for discovery and lightweight checks, alongside offensive automation in Python, Bash and PowerShell.
Read the storySecurity engineering
Test the assumptions
Translate attack paths into telemetry and detection requirements, then validate security controls against observed behaviour. Explore Sentinel use-case development and Kerberos/NTLM authentication analysis.
All cards in this section are viewed.
Turn Red Team findings into engineering priorities
Security Engineering / Detection Use CasesMapped 29 Red Team techniques and signals into 26 prioritised detection, hunting and engineering items, with ATT&CK mappings and telemetry dependencies.
Read the storyFrom business risk to detection
Detection Engineering / Detection as CodeBuilt a governed Sentinel detection workflow, supported versioned KQL, and co-developed a model linking business threats to telemetry and validation.
Read the storyVerify the behaviour behind an identity change
Identity & Security Control AssuranceAnalysed a SecurityEvent export exceeding 100 MB and confirmed Kerberos activity on all 13 servers in an NTLMv2 change review.
Read the storySecurity leadership
Develop the team
Lead SOC and incident-response work, develop analysts through technical coaching and investigation review, and coordinate offensive assessment delivery. Explore how I connect technical decisions with service ownership.
All cards in this section are viewed.
SOC leadership and incident response across client environments
MSSP Security Operations & Incident ResponseLed SOC shifts and incident response using MSSP SIEM and SOAR, correlating endpoint, identity and network evidence across a service supporting 70,000+ endpoints and 150+ clients.
Read the storyCNI SOC leadership and investigation standards
Security Operations LeadershipOnboarded six SOC colleagues, defined investigation quality criteria and coached analysts on AiTM, NAT and identity attacks while providing management cover.
Read the storyKeeping response operational through an MDR transition
SOC Continuity & Service LeadershipLed SOC continuity during an MDR provider transition, then shaped the replacement service across Microsoft Sentinel, ServiceNow SIR and XSOAR.
Read the storyTechnical oversight of an offensive security service
Offensive Security LeadershipOversaw a team portfolio of 50+ monthly offensive engagements, reviewing scope, technical findings and remediation reports and resolving delivery obstacles.
Read the storySoftware development
Build. Operate. Improve.
Build and maintain PHP applications across Linux, Nginx, MySQL, WordPress and Craft CMS. Follow the production debugging, database migrations and developer handovers behind my engineering foundation.
All cards in this section are viewed.
Learning & recognition
Distinction, with breadth
Distinction in Computer Science and Information Security, full scholarships and postgraduate research into ransomware key management and recovery. Explore the academic and community work behind that technical foundation.
All cards in this section are viewed.