AI-Assisted Fraud Review
Collects the context a fraud analyst needs on a signup from a dozen scattered sources into one auditable report, with an advisory LLM verdict. Nothing blocks or approves — a human still decides.
Engineering solutions for operational security problems
Collects the context a fraud analyst needs on a signup from a dozen scattered sources into one auditable report, with an advisory LLM verdict. Nothing blocks or approves — a human still decides.
Reads a supply-chain advisory, extracts every affected package, checks them against our own environment, and prices the triage it replaced. Built in 48 hours.
Runbook-driven agent graph that reads a human-written runbook, gathers the evidence it names across SIEM and ticketing, and produces a critiqued triage report. New alert types onboard as Markdown, not code.
ML-based scoring engine identifying bot/fraud-driven account registrations via structural pattern analysis.
Exports SIEM detections and dashboards to Git as versioned YAML every night. Content-hash diffing keeps the history real, retired rules are archived rather than vanishing, and each run opens one auto-merging review.
Answers "are we running the compromised package?" in seconds — fanning a version spec out to Wiz SBOM and code scanning at once. Also reverse-looks-up Chrome extension installs across managed devices.
Extended an open MCP server to analyze internal SIEM detections alongside public rule sets, enabling automated MITRE ATT&CK coverage tracking and gap analysis.
Falco-based runtime detection stack converting syscall alerts into enriched, investigation-ready insights through AI-assisted analysis.
Built a fully automated CI/CD pipeline for SIEM applications delivery. Eliminated manual packaging and testing , reduced deployment time from hours to minutes.