CYBERSECURITY PORTFOLIO

Daniel Nascimento

Detection engineering for hybrid IT/OT environments

Detection engineering on Wazuh, vulnerability management with DefectDojo, SOAR pipeline in a single-tenant enterprise environment. Defender with an offensive mindset.

// São Paulo, BR available Q2 2026 daniel_sec_jobs@outlook.com
daniel@soc — zsh — 80×24
daniel@soc:~$ whoami
Daniel Nascimento · Cybersecurity Analyst (Mid-Senior)
São Paulo · BR · remote · hybrid · relocation
daniel@soc:~$

// ABOUT

About

Cybersecurity Analyst (Mid-Senior) at eSecurity since Feb/2023, embedded in a single enterprise client (Client A) operating as the de-facto blue team. Coverage spans detection engineering on Wazuh with cluster sizing based on real telemetry, an end-to-end vulnerability management program via DefectDojo (growing scope of web applications), endpoint security on CrowdStrike and Microsoft Defender, a SOAR pipeline in production (TheHive + Cortex + n8n) and recurring AD hardening. Differentiator: cross-period architectural continuity — every technical decision connects to prior ones, forming 2-3 year evolution arcs instead of isolated changes.

Stack I operate in depth: Wazuh, CrowdStrike (CQL, custom IOA rules), Microsoft Defender, MISP, DefectDojo + Acunetix/Nessus/ProjectDiscovery/Nuclei, F5 BigIP (TCL iRules), ModSecurity — including my own ModSec Sync in Flask/Python on port 10080, in production synchronizing WAF rules cross-distro — pfSense/Suricata, BloodHound/PingCastle/Purple Knight, TheHive/Cortex/n8n, Microsoft Purview. Areas I am still honestly developing: Python beyond operational scripting, OpenSearch cluster fine-tuning. Personal setup: a parallel homelab on Oracle Cloud (Docker + Traefik + Cloudflare tunnels + AdGuard) and Notion as documentation hub — a habit publicly recognized by the team senior as "maintainer of the stack documentation".

EXPERIENCE

Experience

  1. present

    Cybersecurity Analyst (Mid-Senior) · eSecurity

    Blue team embedded in a single enterprise client (Client A), with shared ownership of the SOC stack — detection engineering on Wazuh, end-to-end vulnerability management program, multi-engine SOAR pipeline and custom detection rules on CrowdStrike Falcon. Recognized by the team senior as the maintainer of the stack documentation.

    • Wazuh SIEM — 3 years of cluster evolution: architected the transition from standalone manager with stock rules to a multi-node deployment sized through capacity planning based on real telemetry. Authored 100+ custom detection rules — PCRE2 XSS, AD bruteforce tuning, Vulnerability Detection module with inventory at scale — and proposed centralization strategy replacing the current NG-SIEM.
    • End-to-end vulnerability management program as one of the responsibles: designed the DefectDojo pipeline with multi-scanner ingestion (Nessus + Acunetix + ProjectDiscovery), PT-BR translation automation for findings in bulk via Google Cloud Translate, priority dashboard by severity × product × region, and remediation SLA covering a growing scope of web applications. Program extended to Attack Surface Management after Censys × ProjectDiscovery comparison (86 vs. 159 domains mapped) — vendor negotiations reduced total cost by ~US$30k over 12 months.
    • SOAR pipeline (TheHive + Cortex + n8n) in production: orchestrated containment via 3 integrated responders — CrowdStrike Falcon, Microsoft Defender, F5 BigIP — with dual auto/manual flow preserving human approval on network blocks. IOC blocking MTTD went from ~30min manual to <2min automated; NOC gained self-service case creation via TheHive without escalating to an analyst.
    • Detection engineering on CrowdStrike Falcon: led 11-week comparative POC SentinelOne × CrowdStrike with 10 structured scenarios derived from real incidents (Win + Linux). Delivered 5 custom IOA rules in production (detect/kill mode, validated kill of /usr/bin/dash) which became permanent capability of the detection program even after the decision to keep CrowdStrike.
    • Owned components and hardening at scale: ModSec Sync in Flask/Python on port 10080, synchronizing WAF rules cross-distro with git-based versioning and Cortex responder for layer-7 blocking. CIS L1 scripts published for 10 platforms (6 Linux + 4 Windows: RHEL 7/8, Debian 11, Ubuntu 18/20/22, Windows 10/Server 2012R2/2016/2019), adopted by the Networks team as the corporate hardening standard.
    • Incident response technical leadership: night-shift focal point on credential compromise and lateral movement cases — Linux privilege escalation case (91 emails extracted, 835 accounts validated via SocRadar API), utilman.exe bypass, large-scale Entra ID MFA incident, post-RDS forensic collection, EdgeWebView2/DNS-poisoning. Publicly recognized by the team senior as "maintainer of the stack documentation" and designated technical escalation point for the junior on holiday rotation.
    WazuhCrowdStrike FalconMicrosoft DefenderTheHiveCortexn8nDefectDojoProjectDiscoveryF5 BigIPModSecurityMITRE ATT&CK
  2. Cybersecurity Analyst · eSecurity

    First allocation in offense-for-defense work at eSecurity. Internal pentest, federated password spraying respecting lockout policies, SMB/AD enumeration at scale, Active Directory hardening with Lithnet/OpenPasswordFilter and identification of GPO-based privilege escalation path.

    • Internal pentest respecting lockout policies: wordlists derived from typical corporate patterns, valid credential capture via federated password spraying, ADFS endpoint identification and exploitation of the wsignin1.0 flow. Formal deliverables in PDF/DOCX for the customer.
    • Active Directory hardening: configured Lithnet AD Password Protection + OpenPasswordFilter for a proactive password policy, validated in lab the blocking of compromised passwords, executed SharpHound + Purple Knight + PingCastle on the customer AD and produced a prioritized remediation plan.
    • SMB/AD enumeration at scale: null-session and ADMIN$/C$/IPC$ share verification across ~4,274 hosts in the assessment cycle, correlation with Nessus findings, enumeration of accounts with PreauthNotRequired via PowerView.
    • Identified privilege escalation paths via group with write permission on GPO linked to broad OU (excluding only DCs and Domain/Enterprise Admins) — analysis shared with the customer as basis for AD remediation.
    • Recurring deliverables and honest OT/SCADA exposure: produced pentest reports, hardening plans and remediation documentation throughout the customer engagement, with Nessus containerized on Docker for recurring scans. Identified RCE on an industrial server via outdated service, validated exploitability in lab, and contributed to remediation planning. No work with industrial protocols or large-scale OT architecture.
    PingCastleBloodHoundPurple KnightPowerViewLithnetOpenPasswordFilterNessusADFS
  3. Data Center Technician · AWS (Amazon Web Services)

    12-month internship at an AWS data center — first formal exposure to infrastructure operations at hyperscaler scale. Hardware networking, hands-on troubleshooting, strict change management under rigorous runbooks. Operational discipline that underpins my detection engineering work today.

    • Physical infrastructure operations at hyperscaler scale: bench work on rack and network gear in an AWS data center, under approved change windows and formal rollback procedures — 12 months of continuous exposure to rigorous runbooks and blast-radius awareness.
    • First formal exposure to cloud-scale infrastructure: capacity planning, electrical and cooling redundancy, production maintenance flow in a multi-tenant environment — operational foundation that today underpins technical conversations with SREs and SOC capacity planning.
    • Operational discipline inherited from the hyperscaler: change discipline, runbook obsession and "production-first" posture — principles later applied to detection engineering (never run a new rule in production without prior lab validation) and to SIEM architecture (capacity-justified vs. capacity-guessed).

SKILLS

Technical stack

SIEM & Detection

WazuhSigmaOpenSearchGraylogregex/decoders customMITRE ATT&CKFilebeat

EDR

CrowdStrike FalconCQL · RTR · IOA customSentinelOne (POC lead)Microsoft Defender for EndpointSysmon

Vulnerability Management

DefectDojoAcunetixNessusProjectDiscoveryNuclei

Active Directory

BloodHoundPingCastlePurple KnightPowerViewImpacketRubeusLithnetOpenPasswordFilterADFS

Network & WAF

CheckPointF5 BigIP (iRules TCL)iControl RESTModSecurityModSec Sync (Flask/Python)pfSenseSuricataZeek

Cloud & Identity

AWS (CloudTrail · IAM · S3)Azure AD/EntraMicrosoft 365Microsoft PurviewMicrosoft Graph API

SOAR & Pipeline

TheHiveCortex (Responders)n8nDiscord/Teams webhooksNGINX Proxy Manager

Threat Intelligence

MISP (5 feeds)CrowdStrike CTICISA KEVCVSSEPSSSocRadar

Hardening & Compliance

CIS Benchmarks L1RHEL 7/8Debian 11Ubuntu 18/20/22Windows 10/Server 2012R2/2016/2019LynisAtomic Red Team

Scripting & Automation

PythonFlaskBashPowerShellGitREST APIs (CrowdStrike · Graph · BigIP iControl · SocRadar)

HOME LAB · highlight

SOC Home Lab

Personal functional SOC on Proxmox VMs (8 VMs · 32 GB RAM, ongoing since 03/2023). Wazuh + OpenSearch ingesting events from Windows AD, Linux, pfSense, and Suricata. Sigma rules versioned in Git, mapped to MITRE ATT&CK, tested pre-merge in CI. Isolated research environment — metrics below are lab data, not corporate production.

Lab metrics · last 30 days · research environment
ARCHITECTURE deep dive
pfSense Suricata IDS Wazuh manager
DC01-LAB (AD) Sysmon + WEF
WKSTN-01..04 Wazuh agent
OpenSearch + Sigma rules alerts · dashboards · hunts

Sigma rules

52 *
+4 this month

Events/day

340K *
rolling 7d

MTTD

6m 48s *
−22% vs baseline

TTPs covered

37 *
MITRE ATT&CK
NOTABLE DETECTIONS
  • T1558.003 Kerberoasting via TGS 0x17 high
  • T1003.006 DCSync replication rights abuse critical
  • T1558.004 AS-REP Roasting (no preauth) high
  • T1059.001 PowerShell encoded command medium
  • T1110.001 SSH brute force via pfSense medium

CERTIFICATIONS

Credentials

CONTACT

Let’s talk about a senior role.

Detection Engineering, Threat Hunting, or Security Operations. Remote, SP hybrid, or international relocation.

In the first month I deliver: an honest review of the current detection stack, a gap map against MITRE ATT&CK, and 3–5 Sigma rules prioritized by business risk.