SOC Analyst Level 3 | Investigations | Offensive security | Engineering

Ciaran Byrne

Security operations informed by offensive research, forensics, and engineering

I work in enterprise security operations, investigating incidents, hunting for threats, and moving complex cases towards containment and response. My offensive work includes Windows payload development, exploit proofs of concept, internal-network pivoting, web application assessment, and the design of deliberately vulnerable cyber ranges. I use that attacker view to understand which controls failed, what evidence an action leaves, and which change actually makes a system harder to compromise.

Areas of work

Security operations, offensive research, forensics, and engineering

Security operations

Enterprise incident investigation, threat hunting, endpoint analysis, containment, escalation, and response handover.

Offensive security

Payload development, exploit validation, routed pivoting, web application testing, Active Directory attack paths, and adversary simulation in authorised environments.

Forensics and analysis

Malware analysis, network forensics, event correlation, reverse engineering, and evidence-led technical reporting.

Engineering

Cyber ranges, segmented infrastructure, backend services, automation, and the systems needed to make security work repeatable.

Archive

Earlier technical work and coursework

The archive contains earlier work from systems administration, scripting, memory safety, embedded development, networking, and foundational security. It remains available as part of the progression towards the more complete work published across the rest of the site.

Browse the archive