DetectionMITRE ATT&CKCloud

Detection & Response Modernization

Re-architected the detection stack across identity, endpoint, and cloud, mapping coverage to MITRE ATT&CK and cutting mean time to detect for high-severity alerts.

Challenge

The existing monitoring approach missed AI-enabled identity misuse and lacked cloud-native threat context.

Approach

I aligned detections with ATT&CK tactics, standardized telemetry across workloads, and built a response framework for high-risk AI and cloud incidents.

Outcome

The modernization effort delivered faster incident validation, clearer investigator workflows, and stronger coverage for identity and model access anomalies.

Back to projects
Explore the page for practical AI security outcomes and architectural details.