Defensive security
SIEM and SOC implementation, detection engineering, threat hunting, SOAR, incident response and forensics. Sentinel, Splunk, CrowdStrike, KQL.
Type help for the list of commands. Arrow keys for history, Tab to autocomplete.
Enter a command. Use the up and down arrow keys for command history and Tab for autocomplete.
Defend & monitor
SIEM and SOC implementation, detection engineering, threat hunting, SOAR, incident response and forensics. Sentinel, Splunk, CrowdStrike, KQL.
Azure, IAM, networking, CIS benchmarks, Kubernetes, Intune and DevSecOps reviews.
Asset discovery, vulnerability assessment and posture reviews in industrial environments.
Assess & govern
External exposure discovery, OSINT, breach intelligence, metadata analysis and the automation behind it.
Authorised penetration testing of web applications, infrastructure and mobile platforms, plus purple-team and physical-security exercises. Burp Suite, Nmap, Kali, OWASP.
ISMS, ISO 27001, NIS2 and CyFun, risk management and cyber due diligence.
Recurring engagement types from four years of client delivery, plus the internal tooling built to support them.
Cyber risk assessments run as part of acquisition due diligence, scoped and delivered across multiple regions, feeding findings into the deal timeline alongside the legal and financial workstreams.
Internal tooling that continuously maps a client's external footprint: domains, exposed services, certificates and leaked credentials, correlated into a single view of what an outsider can actually see.
Microsoft Sentinel deployments from architecture through go-live: log source onboarding, analytics rules, SOAR playbooks and handover to the client's own SOC team.
An internal web app that watches Sentinel log sources and flags what needs attention: sources gone quiet, ingestion costs drifting out of range, connectors reporting unhealthy.
The card grid above generalises real engagement types; client names and specifics stay confidential.
Four years at EY, on projects in government, transport, pharmaceuticals, food production and critical infrastructure. Most engagements move between architecture, investigation and hands-on testing, and end with something the client's own team has to be able to run.
All offensive, phishing, physical-security and acquisition assessments described on this site were carried out as authorised professional work.
Bachelor Information Security, Thomas More
Dutch, French, English
FPV drones and 3D printing - flight films and builds.