whoami.sh

👋 It's nice to meet you, I'm Oi, prazer, me chamo Joao Marcelo João Marcelo

Cybersecurity engineer with hands-on experience in Microsoft Sentinel and Defender XDR. I reconstruct incidents from telemetry and turn what I find into detections that actually hold up. Engenheiro de Cibersegurança com experiência prática em Microsoft Sentinel e Defender XDR. Reconstruo incidentes a partir de telemetria e transformo o que encontro em detecções que realmente funcionam.

01 — Selected work 01 — Trabalho Selecionado

Featured investigations Investigações em Destaque

Threat hunts and DFIR case studies I ran and documented end to end. Threat hunts e estudos de caso DFIR que conduzi e documentei do início ao fim.

All projects → Todos os Projetos →

DFIR Case Study: Azure Control-Plane Domain Compromise Estudo de Caso DFIR: Comprometimento do Plano de Controle do Azure

Microsoft SentinelDefender XDRKQLREMnux

Reconstructed a simulated 17-hour domain compromise across three hosts using 28 documented KQL queries against Sentinel and Defender XDR. Traced an Azure Run Command privilege-escalation bypass and an AdminSDHolder ACL backdoor, then authored and validated new detection rules — correcting a KQL tokenization defect that had hidden a second attacker session. Reconstruí um comprometimento de domínio simulado de 17 horas em três hosts usando 28 queries KQL documentadas contra o Sentinel e o Defender XDR. Rastreei um bypass de escalonamento de privilégios via Azure Run Command e um backdoor de ACL no AdminSDHolder, e então criei e validei novas regras de detecção — corrigindo um defeito de tokenização em KQL que havia ocultado uma segunda sessão do atacante.

Internal Threat Hunt: Network Slowdown Traced to LotL Port Scan Threat Hunt Interno: Lentidão de Rede Rastreada a um Port Scan LotL

Microsoft Defender for EndpointKQLPowerShell

Traced a network performance complaint to a PowerShell port scanner run twice against two internal hosts in a self-staged MDE lab. The obvious query — ranking hosts by total failed connections — missed the responsible host entirely; attributing failures to process and scoring ports-per-host surfaced it by two orders of magnitude. Recovered the exact command line, mapped the activity to MITRE ATT&CK (T1059.001, T1046), and shipped a ports-per-host detection rule with segmentation and PowerShell-constraint recommendations. Rastreei uma reclamação de desempenho de rede até um port scanner em PowerShell executado duas vezes contra dois hosts internos em um laboratório MDE que montei. A query óbvia — classificar hosts pelo total de conexões falhadas — errou completamente o host responsável; atribuir as falhas ao processo e calcular portas-por-host o revelou por duas ordens de grandeza. Recuperei a linha de comando exata, mapeei a atividade ao MITRE ATT&CK (T1059.001, T1046) e entreguei uma regra de detecção baseada em portas-por-host, com recomendações de segmentação e de restrição do PowerShell.

Vulnerability Management Lab: Tenable Scan-to-Remediation Cycle Laboratório de Gestão de Vulnerabilidades: Ciclo de Scan à Remediação com Tenable

Tenable NessusAzurePowerShell

Ran authenticated Tenable Nessus scans against an intentionally unhardened Windows Server VM in Azure to establish a vulnerability baseline, then prioritized findings by CVSS and business impact. Remediated six categories of exposure — missing OS updates, an over-privileged local Guest account, outdated third-party software, disabled SMB signing, missing RDP Network Level Authentication, and legacy LM/NTLMv1 authentication — verifying each fix with a post-remediation delta scan. Reduced active vulnerabilities from 24 to 4, an 83% reduction. Executei scans autenticados com o Tenable Nessus contra uma VM Windows Server propositalmente não hardenizada no Azure para estabelecer um baseline de vulnerabilidades, priorizando os achados por CVSS e impacto ao negócio. Remediei seis categorias de exposição — atualizações de SO ausentes, uma conta Guest local com privilégios excessivos, software de terceiros desatualizado, SMB signing desabilitado, ausência de Network Level Authentication no RDP e autenticação legada LM/NTLMv1 — verificando cada correção com um delta scan pós-remediação. Reduzi as vulnerabilidades ativas de 24 para 4, uma redução de 83%.

Scroll down

02 — Stack 02 — Tecnologias

Skills and tools Habilidades e Ferramentas

The platforms I work in daily, and the tooling I practice with outside of work. As plataformas com as quais trabalho diariamente, e as ferramentas com as quais pratico fora do trabalho.

SOC and detection engineering SOC e Engenharia de Detecção
Microsoft SentinelDefender XDRDefender for EndpointKQLMITRE ATT&CKSysmon
Hardening and vulnerability management Hardening e Gestão de Vulnerabilidades
PowerShellDISA STIGTenable NessusAzureActive Directory
Hands-on practice · TryHackMe Prática Hands-on · TryHackMe
NmapMetasploitHydraMimikatzLinuxREMnux
Scroll down

03 — What I do 03 — O Que Eu Faço

Areas of focus Áreas de Atuação

Six things I spend my time on, roughly in order of how much of it they take. Seis coisas nas quais dedico meu tempo, aproximadamente em ordem de quanto tempo elas ocupam.

01

Threat Hunting & Detection Engineering Threat Hunting e Engenharia de Detecção

Running proactive threat hunts across endpoint, identity, and network telemetry, and authoring detection rules to catch techniques that produce no alert. Conduzindo threat hunts proativos em telemetria de endpoint, identidade e rede, além de criar regras de detecção para capturar técnicas que não geram alertas.

02

Incident Response & DFIR Resposta a Incidentes e DFIR

Reconstructing attacker timelines from Sentinel, Sysmon, and Windows Event Log telemetry, mapping activity to MITRE ATT&CK, and delivering documented incident reports. Reconstruindo linhas do tempo de ataque a partir de telemetria do Sentinel, Sysmon e Windows Event Log, mapeando atividades ao MITRE ATT&CK e entregando relatórios de incidente documentados.

03

KQL & Log Analysis KQL e Análise de Logs

Writing KQL against Microsoft Sentinel and Defender XDR tables to isolate suspicious activity, correlate telemetry, and validate detection coverage. Escrevendo KQL contra tabelas do Microsoft Sentinel e Defender XDR para isolar atividades suspeitas, correlacionar telemetria e validar a cobertura de detecção.

04

Static Malware Analysis Análise Estática de Malware

Triaging suspicious artifacts on an isolated REMnux VM using hashing, strings, PE parsing, binwalk, and XOR decoding to identify malware behavior. Triando artefatos suspeitos em uma VM REMnux isolada usando hashing, strings, parsing de PE, binwalk e decodificação XOR para identificar o comportamento do malware.

05

System Hardening & Vulnerability Management Hardening de Sistemas e Gestão de Vulnerabilidades

Auditing and remediating Windows systems against DISA STIG controls, running authenticated Tenable Nessus scans to baseline and prioritize vulnerabilities by CVSS, and verifying remediation with delta scans. Auditando e corrigindo sistemas Windows conforme os controles DISA STIG, executando scans autenticados com o Tenable Nessus para estabelecer um baseline e priorizar vulnerabilidades por CVSS, e verificando a remediação com delta scans.

06

Cloud & Identity Security Segurança de Nuvem e Identidade

Securing Microsoft Azure and Active Directory environments, analyzing identity telemetry, and applying NIST-aligned risk management practices. Protegendo ambientes Microsoft Azure e Active Directory, analisando telemetria de identidade e aplicando práticas de gestão de risco alinhadas ao NIST.

Scroll down

04 — Experience 04 — Experiência

Where I've worked Onde Já Trabalhei

Cybersecurity Engineer (Intern) Engenheiro de Cibersegurança (Estágio) LOG(N) Pacific
Jun 2026 — Aug 2026 Jun 2026 — Ago 2026 · Remote Remoto
  • Ran proactive threat hunts across endpoint and network telemetry in Sentinel and Defender for Endpoint. Conduzi threat hunts proativos em telemetria de endpoint e rede no Sentinel e no Defender for Endpoint.
  • Authored KQL against DeviceNetworkEvents and DeviceProcessEvents — traced a living-off-the-land PowerShell port scan through 100+ failed internal connections. Escrevi KQL nas tabelas DeviceNetworkEvents e DeviceProcessEvents — rastreei um port scan living-off-the-land via PowerShell através de mais de 100 tentativas de conexão interna falhadas.
  • Mapped process execution and network telemetry to MITRE ATT&CK to support root-cause analysis. Mapeei a execução de processos e a telemetria de rede ao MITRE ATT&CK para apoiar a análise de causa raiz.
  • Audited and remediated Windows systems against DISA STIG controls, implementing 10+ hardening tasks across account policy, credential settings, and administrative restrictions. Auditei e corrigi sistemas Windows conforme os controles DISA STIG, implementando mais de 10 tarefas de hardening em políticas de conta, configurações de credenciais e restrições administrativas.
Microsoft AzureMicrosoft SentinelMicrosoft Defender for EndpointKQLNessus TenableMITRE ATT&CKDISA STIGPowerShell
Scroll down

05 — Education 05 — Formação

Studies Formação Acadêmica

B.S. in Computer Science Bacharelado em Ciência da Computação

Western Governors University — Completed July 2025 Western Governors University — Concluído em julho de 2025

Core CS foundations: data structures, algorithms, operating systems, networking, and databases. Fundamentos essenciais de Ciência da Computação: estruturas de dados, algoritmos, sistemas operacionais, redes e bancos de dados.

Data Structures & Algorithms I & IISoftware I & IIOperating SystemsDatabasesNetworkingCalculusDiscrete Mathematics I & II

M.S. in Cybersecurity & Information Assurance Mestrado em Cibersegurança e Garantia da Informação

Western Governors University — Paused (50% complete) Western Governors University — Pausado (50% concluído)

Advanced coursework in threat hunting, incident response, and detection engineering, building directly on hands-on SOC work with Microsoft Sentinel, Defender XDR, and MITRE ATT&CK. Disciplinas avançadas em threat hunting, resposta a incidentes e engenharia de detecção, construídas diretamente sobre o trabalho prático em SOC com Microsoft Sentinel, Defender XDR e MITRE ATT&CK.

Threat HuntingIncident ResponseDetection EngineeringRisk ManagementNetwork Defense
Separator