Signal over noise.
I'm Elmer Phillips, a Security Analyst triaging alerts, hunting threats, and writing up what I learn from inside the SOC.
How I approach the work
Security Analyst with 4+ years of MDR experience, triaging alerts, hunting through SIEM data, and investigating suspicious activity across customer environments.
- Blue Team Operations & Defense
- SIEM & EDR Platform Mastery
- Detection Engineering & Threat Hunting
- Pragmatic Incident Response
Featured Blog Posts
All postsAn IRS-Themed Lure Installing Signed RMM Tooling
A user ran a file called ID.me_IRS_VM_REC_Secure_Verification_Gateway-1664459__<date>-166445992WW.EXE out of their Downloads …
Read MoreWhen "ollama.js" Isn't Ollama
A file named ollama.js came off a host that already had a working Ollama installation, which put both the file name and the …
Read MoreBuilding Threatweave
A few months ago I was triaging a suspicious IP with VirusTotal, AbuseIPDB, Shodan, and OTX open in four tabs, reconciling the …
Read More
What I bring to the SOC
Blue Team Operations
- Defensive playbooks
- SOC workflows
SIEM Platforms
- Splunk, Microsoft Sentinel, Chronicle
EDR Solutions
- SentinelOne, CrowdStrike, Defender
Threat Intel & Hunting
- OSINT enrichment, hunt hypotheses
Detection Eng. & IR
- Rule tuning, incident response
Let’s talk security.
Open to conversations about detection engineering, threat hunting, or MDR operations. Reach out any time.