Grom-Lab notebook · Est. 2024
Security engineering,
tested properly.
I'm Mitch, a Cyber Security Engineer. This is where I document Azure architecture, threat modelling, detection engineering and the research behind my MSc.
Experiment 001 · MSc final project
Can CVSS predict real-world exploitation?
I tested CVSS, EPSS, logistic regression and XGBoost on 71,224 vulnerabilities published after the training period. EPSS identified substantially more confirmed exploits when patching capacity was limited.
Read the full project write-up →From the lab book
Selected projects
Predicting real-world vulnerability exploitation
A strict temporal evaluation of CVSS, EPSS and machine-learning models against confirmed exploitation in CISA KEV.
Open case study →Project Atlas: secure Azure SaaS architecture
An industry-neutral SaaS scenario translating availability, identity, data and operational requirements into a secure, testable Azure target state.
Open case study →Scattered Spider-style identity intrusion
An eight-stage attack path against Project Atlas, mapped to preventative controls, response actions and practical KQL detections.
Open case study →Vendor-agnostic security monitoring engineering
A working telemetry pipeline covering collection, normalisation, enrichment, stream routing, tiered retention and detection validation.
Open case study →About the engineer
Designed, built and tested.
My work covers cloud and identity architecture, network access control, detection engineering, vulnerability management and incident response. I have designed Azure controls around Zero Trust and the Cloud Adoption Framework, built monitoring and response workflows, and mapped technical controls to ISO 27001, NIST and business risk.
The case studies on this site describe the engineering decisions and methods without publishing confidential employer designs.
View LinkedIn profile →