Grom-Lab notebook · Est. 2024

Security engineering,
tested properly.

I'm Mitch, a Cyber Security Engineer. This is where I document Azure architecture, threat modelling, detection engineering and the research behind my MSc.

MSc Cyber Security & Digital ForensicsSC-100 · AZ-500 · Security+Bristol, UK

Experiment 001 · MSc final project

Can CVSS predict real-world exploitation?

I tested CVSS, EPSS, logistic regression and XGBoost on 71,224 vulnerabilities published after the training period. EPSS identified substantially more confirmed exploits when patching capacity was limited.

Read the full project write-up →
71,224CVEs in held-out test set
0.136EPSS PR-AUC
0.010CVSS PR-AUC
34.1% vs 4.3%Exploits found at 5% capacity

About the engineer

Designed, built and tested.

My work covers cloud and identity architecture, network access control, detection engineering, vulnerability management and incident response. I have designed Azure controls around Zero Trust and the Cloud Adoption Framework, built monitoring and response workflows, and mapped technical controls to ISO 27001, NIST and business risk.

The case studies on this site describe the engineering decisions and methods without publishing confidential employer designs.

View LinkedIn profile →