NO ENTRY — Multi-Tier Threat Intelligence & Detection Engineering Platform
70%+ analyst noise reduction · 52 MITRE techniques · Splunk SPL · Sentinel KQL · Sigma YAML
Designed and deployed a complete SOC intelligence and alert triage ecosystem. Ingests 100+ global cyber feeds (CISA, BleepingComputer, THN) into PostgreSQL with automated IOC extraction, enriches via VirusTotal, AbuseIPDB & CISA KEV, dynamically maps threats to the MITRE ATT&CK heat matrix, and auto-compiles detection rules — with a TF-IDF AI microservice cutting alert noise by 70%+.