I build practical security operations capabilities: detection engineering, incident response, threat hunting, intelligence workflows, DFIR tooling, and low-cost security architecture for teams that need security outcomes they can deploy, inspect, and maintain.
| Area | Current Focus |
|---|---|
| π‘οΈ Security Operations | SOC engineering, alert triage, case workflow, response playbooks |
| π― Detection Engineering | Sigma, SIEM/XDR content, MITRE ATT&CK mapping, multi-platform rules |
| π΅οΈ Threat Hunting | IOC/IOA hypothesis building, telemetry pivoting, adversary behavior tracking |
| π§ͺ DFIR | Log analysis, forensic triage, incident reconstruction, investigation tooling |
| π°οΈ Threat Intelligence | IOC enrichment, CVE prioritization, OSINT collection, operational reporting |
| ποΈ Security Architecture | Low-cost security architecture, platform integration, defense capability roadmaps |
| βοΈ Automation | Python, JavaScript, Docker, API integration, SOAR workflow automation |
| βοΈ Cloud Security | AWS/Azure/GCP hardening, Kubernetes, compliance automation, IaC security |
|
Cross-platform security baseline auditing and controlled remediation for Linux, macOS, Windows, FreeBSD, Alpine, AWS, Azure, GCP, Kubernetes, Docker, and more. Audit β Plan β Apply β Rollback. |
Cross-platform detection library β 836 rules, 9 platforms, 152 MITRE ATT&CK techniques. Sigma Β· Elastic Β· Splunk Β· Sentinel Β· Wazuh Β· Carbon Black Β· CrowdStrike Β· SentinelOne Β· Falco. |
|
Convert YARA rules to Sigma detections and native SIEM/EDR queries with .yar import, IOC classification, MITRE ATT&CK tagging, CLI, API, and Docker. |
Centralized threat intelligence and security operations platform for advisories, CVEs, IOCs, alert context, and case workflows. |
|
Threat analysis and digital forensics platform with log and network analyzers, memory triage, Sigma correlation, and MFA-enabled administration. |
Threat hunting playbook engine for repeatable hunts, evidence tracking, ATT&CK coverage analysis, and analyst-ready reports. |
|
Vulnerability management dashboard for tracking, prioritizing, and visualizing security findings across teams. |
The Ultimate Multi-IaC Visual Platform. Design infrastructure visually and generate code for Terraform, OpenTofu, Pulumi, or Helm with real-time pricing. |
My hobby is learning new things. These are security, infrastructure, intelligence, automation, and observability tools I have used or recently studied.
- System Engineer / Cyber Security Architect
- Digital Forensics on Corporate
- Trainer Cyber Security on BUMN
- Automation Engineer
- Head of Cyber Security Team
- Learning new security and infrastructure tooling continuously.
- Designing low-cost IT security architecture that is practical to operate.
- Publishing reusable detection engineering and threat hunting content.
- Improving practical SOC, DFIR, and CTI tooling for small and medium security teams.
- Sharing knowledge for the advancement of Indonesian cybersecurity education.



