~$ whoami
Threat Hunting · Digital Forensics · Cloud IR · DFIR
Dedicated Cyber Incident Responder at Salesforce CSIRT, focused on Blue Team operations and defensive security. Experienced in Threat Hunting, Digital Forensics, Incident Response, and Threat Investigation across Windows, Linux, macOS, and multi-cloud environments (AWS, Azure, GCP). Committed to continuous learning and improving detection & response capabilities — from contributing to MITRE ATT&CK to building internal DFIR tooling.
Cyber Incident Responder, CSIRT
Salesforce — Melbourne, Australia
Associate Cyber Incident Response Specialist
EnergyAustralia — Melbourne, Australia
Security Operations Centre (SOC) Supervisor
MPT – KDDI Summit Global Myanmar — Yangon, Myanmar
Cyber Security Analyst
Kernellix — Yangon, Myanmar (Internship)
BTLO Global #1
Blue Team Labs Online — ranked #1 globally across all defenders on the platform.
View Profile →MITRE ATT&CK Contributor
Contributed T1546.018 — Event Triggered Execution: Python Startup Hooks.
View Technique →BSides Myanmar 2025 Speaker
Presented "The Art of Windows Memory Forensics".
2025SANS Offensive Operations Coin
Won the final capstone challenge of SEC504 on the last day of class.
2026SANS Lethal Forensicator Coin
Won the final capstone challenge of FOR508 on the last day of class.
2024GIAC Advisory Board
Awarded by GIAC for outstanding score (90%) on the GCFA exam.
2024Insider Threat Matrix Contributor
Contributed AR5 and DT095 (Uninstalling Software).
View Contribution →BTL2 Silver Challenge Coin
Awarded by Security Blue Team for passing the Blue Team Level 2 exam.
2024GIAC / SANS
8 certifications
EC-Council
1 certification
INE / eLearnSecurity
1 certification
Security Blue Team
1 certification
CyberDefenders
1 certification
TryHackMe
1 certification
Degrees
Master of Information Technology / Master of Business Administration
James Cook University, Australia
Bachelor of Science (Computing)
Edinburgh Napier University, UK
HND in Computing & Systems Development
Info Myanmar University, Myanmar
Courses
FOR508 — Advanced Incident Response, Threat Hunting & Digital Forensics
SANS Institute
FOR518 — Mac and iOS Forensic Analysis and Incident Response
SANS Institute
SEC504 — Hacker Tools, Techniques & Incident Handling
SANS Institute
Investigation Theory
Applied Network Defense — Chris Sanders
Hunting Adversary Infrastructure
IntelOps
SIEM
EDR / XDR
Digital Forensics
Cloud IR
Other
Development
Internal DFIR Tooling
Developed multiple internal DFIR tools across the Cloud Incident Response and Host Forensics space.
TONESHELL Malware Analysis
Threat Intelligence · Malware Analysis
Deep-dive analysis of TONESHELL malware attributed to Chinese APT group Mustang Panda. Published as part of PHK Knowledge Sharing series covering TTPs, C2 infrastructure, and detection opportunities.
Open to collaboration, speaking opportunities, and interesting security problems.