SOC Analyst Level 3 | Investigations | Offensive security | Engineering

Ciaran Byrne

Security operations backed by offensive, forensic, and engineering experience

I work in enterprise security operations, investigating incidents, hunting for threats, and helping move complex cases towards containment and response. I am interested in security as a complete system rather than a set of separate disciplines: how an attacker moves, what the defender can see, and how infrastructure, software, and identity change the options available to both. This site documents the projects, investigations, and research behind that work.

Areas of work

Security operations, offensive research, forensics, and engineering

Security operations

Enterprise incident investigation, threat hunting, endpoint analysis, containment, escalation, and response handover.

Offensive security

Authorised testing, exploit research, adversary simulation, and understanding how attacks work in practice.

Forensics and analysis

Malware analysis, network forensics, event correlation, reverse engineering, and evidence-led technical reporting.

Engineering

Cyber ranges, segmented infrastructure, backend services, automation, and the systems needed to make security work repeatable.

Archive

Earlier technical work and coursework

The archive contains earlier work from systems administration, scripting, memory safety, embedded development, networking, and foundational security. It remains available as part of the progression towards the more complete work published across the rest of the site.

Browse the archive