Josh Strickland
Threat Hunter • Incident Handler

I hunt threats. I stop threats.

Threat hunting and incident handling. I dig through raw telemetry to find what automated tools miss, handle incidents from triage to resolution, and build the platforms that make security operations actually work. Currently at Secnap Network Security.

Josh
0
EDR Platforms Hunted
0
Custom Detections
0
Certifications

Threat Hunting & Incident Handling

🎯

Threat Hunting

Hypothesis-driven hunts across endpoint, cloud, and identity environments. Digging through raw EDR telemetry to surface threats that automated tools don't catch.

🚨

Incident Handling

Triage, investigation, containment, and escalation. Working incidents from first alert to resolution, including direct customer communication during declared incidents.

🔧

SOC Operations

Built the SOC dashboard, workflow system, and response processes from the ground up. Keeping the operation running and making it better every day.

Things I've Actually Found

Secnap

ClickFix Attack via Callstack Analysis

Caught a ClickFix attack through callstack analysis. Explorer.exe with shell32.dll was spawning untrusted processes. Stopped it before NetSupport RAT could deploy.

Red Canary

2-Month VPN Compromise

Found a threat actor sitting in a customer's VPN for two months, undetected, running AD brute force. Built a recurring hunt to cover the gap.

View All Hunts

What I Work With

LimaCharlie CrowdStrike SentinelOne Microsoft Defender Carbon Black Palo Alto Cortex Wazuh Velociraptor Fibratus (ETW) Sigma Rules MITRE ATT&CK Azure Entra ID Active Directory Jupyter / Pandas PowerShell Linux

Want to talk shop?

Always down to connect about threat hunting, incident handling, or anything security.

Get In Touch