Independent defensive security practitioner. I build detections, dig into how real attacks work, and do vCISO work for small and mid-sized teams.
- alias:
0xdev1 - doing: Detection engineering · threat analysis · vCISO for SMBs
- based: Globally / remote
- working in: Sigma, KQL, MITRE ATT&CK, Essential Eight
- rule: Defensive only. Every claim tied to a primary source.
Everything I publish - detections, tooling, and sourced research - lives under the UMBRASEC org and at umbrasec.dev.




