Principal DFIR Technical Architect at Unit 42 by Palo Alto Networks
Building AI-powered solutions for incident response and threat hunting
13+ years responding to major incidents, architecting security solutions, and building detection capabilities at Palo Alto Networks, Rapid7, Liberty Mutual, IBM, and MIT Lincoln Laboratory.
Currently on Unit 42's DFIR Innovation Team, designing scalable solutions that integrate LLMs, automation, and data science to accelerate investigations across cloud, endpoint, and enterprise environments.
50+ hands-on labs teaching security practitioners to build AI/ML tools for threat detection, DFIR, and incident response. Includes Docker environment, Colab notebooks, and CTF challenges.
- Multi-agent systems for automated incident response
- LLM-powered threat hunting and analysis
- XQL query optimization and detection engineering
- Practitioner enablement and open-source tooling
"ML scales detection, LLMs accelerate analysis, humans drive decisions."




